securityonline.info 8/13/2026, 8:52:47 AM · external

Overlord RAT spreads via fake Zoom installer on Mac and Windows

Overlord RAT spreads via fake Zoom installer on Mac and Windows
CyberSIXT Evidence Panel
Primary Source jamf.com

THE content outlines the detection of a critical cybersecurity threat involving a fake Zoom installer that deploys the Overlord remote access tool (RAT) on macOS and Windows. Key points include:

1. **Active Exploits**: Three CVEs have been identified, affecting Cisco Secure Firewall, Microsoft Windows, and Metabase.

2. **Malware Overview**: The Overlord RAT is a cross-platform tool with capabilities including keylogging, screen capture, and remote control.

3. **Delivery Method**: The malware is delivered through a fake installer named ZoomMeetings, which uses a .NET binary, a rare method for Mac malware.

4. **Infection Chain**: The downloader checks the OS and architecture, retrieves malware payloads, and behaves like a legitimate Zoom installer, making it difficult for victims to detect.

5. **Command and Control**: The RAT connects to a server over secure WebSocket, though with certificate validation disabled, offering broad control to the attacker.

6. **Attribution**: The attack is suspected to have DPRK links, but no direct correlation has been confirmed.

7. **Prevention Recommendations**: Users are advised to download Zoom from official sources, monitor for unusual binaries, and keep an eye on outbound connections.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline