{"id":3848,"date":"2022-02-17T12:52:16","date_gmt":"2022-02-17T17:52:16","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3848"},"modified":"2022-02-17T12:52:18","modified_gmt":"2022-02-17T17:52:18","slug":"dont-fall-for-malicious-apps-infected-by-zuru","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/dont-fall-for-malicious-apps-infected-by-zuru\/","title":{"rendered":"Don&#8217;t fall for malicious apps infected by ZuRu"},"content":{"rendered":"\n<p>While most cybercriminals continue to heavily attack Windows machines, there are more daring groups that target more exotic targets, such as macOS systems. ZuRu is one of the last identified malicious programs exclusively targeting Macs. Its creators appear to rely on the list of sponsored search results to try to redirect users to a malicious page. The crooks are actually spoofing the name of a legitimate macOS tool called iTerm2.<\/p>\n\n\n\n<p>Currently, the criminals seem to target only the Chinese search engine Baidu. However, it would not be a surprise if they tried to expand their operation in the near future. Once a user tries to download iTerm from the fake website, they will be referred to a third party hosting service, which will get the iTerm.dmg file. So far, everything looks normal on the user&#8217;s screen; the only red flag is the slightly different domain name. However, most people would not realize this.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What can ZuRu do if it infects you<\/h2>\n\n\n\n<p>If a user is tricked into running the Trojan horse, ZuRu downloads and runs a Python script that collects various information from an infected Mac, including:<\/p>\n\n\n\n<p><strong><em>\u25b8User&#8217;s macOS keychain database<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8Bash and zsh user terminal command history<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8The user&#8217;s iTerm2 stored state<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8User ssh keys and known hosts<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8System, hosts and etc files<\/em><\/strong><\/p>\n\n\n\n<p>Clearly, cybercriminals are experimenting with all sorts of nasty tricks to reach their victims. The ZuRu campaign, in particular, is very intriguing this way. The best way to keep your system and data safe is to use antivirus software and be very careful when browsing the Internet.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>While most cybercriminals continue to heavily attack Windows machines, there are more daring groups that target more exotic targets, such as macOS systems. ZuRu is one of the last identified malicious programs exclusively targeting Macs. Its creators appear to rely on the list of sponsored search results to try to redirect users to a malicious [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3849,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-3848","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Don&#039;t fall for malicious apps infected by ZuRu - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Cybercriminals are increasingly looking for more complex ways to deceive users and today we will see a new threat called ZuRu......\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/dont-fall-for-malicious-apps-infected-by-zuru\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Don&#039;t fall for malicious apps infected by ZuRu - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Cybercriminals are increasingly looking for more complex ways to deceive users and today we will see a new threat called ZuRu......\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/dont-fall-for-malicious-apps-infected-by-zuru\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2022-02-17T17:52:16+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-02-17T17:52:18+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/10\/ZuRu.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1500\" \/>\n\t<meta property=\"og:image:height\" content=\"1000\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-fall-for-malicious-apps-infected-by-zuru\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-fall-for-malicious-apps-infected-by-zuru\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Don&#8217;t fall for malicious apps infected by ZuRu\",\"datePublished\":\"2022-02-17T17:52:16+00:00\",\"dateModified\":\"2022-02-17T17:52:18+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-fall-for-malicious-apps-infected-by-zuru\\\/\"},\"wordCount\":274,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-fall-for-malicious-apps-infected-by-zuru\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/ZuRu.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-fall-for-malicious-apps-infected-by-zuru\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-fall-for-malicious-apps-infected-by-zuru\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-fall-for-malicious-apps-infected-by-zuru\\\/\",\"name\":\"Don't fall for malicious apps infected by ZuRu - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-fall-for-malicious-apps-infected-by-zuru\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-fall-for-malicious-apps-infected-by-zuru\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/ZuRu.jpg\",\"datePublished\":\"2022-02-17T17:52:16+00:00\",\"dateModified\":\"2022-02-17T17:52:18+00:00\",\"description\":\"Cybercriminals are increasingly looking for more complex ways to deceive users and today we will see a new threat called ZuRu......\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-fall-for-malicious-apps-infected-by-zuru\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-fall-for-malicious-apps-infected-by-zuru\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-fall-for-malicious-apps-infected-by-zuru\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/ZuRu.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/ZuRu.jpg\",\"width\":1500,\"height\":1000,\"caption\":\"Cyber Technology Security Protection Monitoring Concept, Advanced Cloud Data Security System, Futuristic Technology Background, 3d Rendering\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-fall-for-malicious-apps-infected-by-zuru\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Don&#8217;t fall for malicious apps infected by ZuRu\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Don't fall for malicious apps infected by ZuRu - Truxgo Server Blog","description":"Cybercriminals are increasingly looking for more complex ways to deceive users and today we will see a new threat called ZuRu......","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/dont-fall-for-malicious-apps-infected-by-zuru\/","og_locale":"es_MX","og_type":"article","og_title":"Don't fall for malicious apps infected by ZuRu - Truxgo Server Blog","og_description":"Cybercriminals are increasingly looking for more complex ways to deceive users and today we will see a new threat called ZuRu......","og_url":"https:\/\/truxgoservers.com\/blog\/dont-fall-for-malicious-apps-infected-by-zuru\/","og_site_name":"Truxgo Server Blog","article_published_time":"2022-02-17T17:52:16+00:00","article_modified_time":"2022-02-17T17:52:18+00:00","og_image":[{"width":1500,"height":1000,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/10\/ZuRu.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/dont-fall-for-malicious-apps-infected-by-zuru\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/dont-fall-for-malicious-apps-infected-by-zuru\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Don&#8217;t fall for malicious apps infected by ZuRu","datePublished":"2022-02-17T17:52:16+00:00","dateModified":"2022-02-17T17:52:18+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/dont-fall-for-malicious-apps-infected-by-zuru\/"},"wordCount":274,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/dont-fall-for-malicious-apps-infected-by-zuru\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/10\/ZuRu.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/dont-fall-for-malicious-apps-infected-by-zuru\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/dont-fall-for-malicious-apps-infected-by-zuru\/","url":"https:\/\/truxgoservers.com\/blog\/dont-fall-for-malicious-apps-infected-by-zuru\/","name":"Don't fall for malicious apps infected by ZuRu - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/dont-fall-for-malicious-apps-infected-by-zuru\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/dont-fall-for-malicious-apps-infected-by-zuru\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/10\/ZuRu.jpg","datePublished":"2022-02-17T17:52:16+00:00","dateModified":"2022-02-17T17:52:18+00:00","description":"Cybercriminals are increasingly looking for more complex ways to deceive users and today we will see a new threat called ZuRu......","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/dont-fall-for-malicious-apps-infected-by-zuru\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/dont-fall-for-malicious-apps-infected-by-zuru\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/dont-fall-for-malicious-apps-infected-by-zuru\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/10\/ZuRu.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/10\/ZuRu.jpg","width":1500,"height":1000,"caption":"Cyber Technology Security Protection Monitoring Concept, Advanced Cloud Data Security System, Futuristic Technology Background, 3d Rendering"},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/dont-fall-for-malicious-apps-infected-by-zuru\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Don&#8217;t fall for malicious apps infected by ZuRu"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3848","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3848"}],"version-history":[{"count":1,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3848\/revisions"}],"predecessor-version":[{"id":3850,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3848\/revisions\/3850"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3849"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3848"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3848"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3848"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}