Home Hardware Audio Gear Fake Zoom, Slack Apps Spread macOS Malware Sonoma

Fake Zoom, Slack Apps Spread macOS Malware Sonoma

0
Fake Zoom, Slack Apps Spread macOS Malware Sonoma
Fake Zoom, Slack Apps Spread macOS Malware Sonoma

A newly identified macOS malware strain named Sonoma is being distributed through fake installers mimicking popular productivity and communication apps, including Zoom, Slack, StreamYard, and DocSend. According to research from Moonlock, the cybersecurity division of MacPaw, threat actors are using these deceptive files to trick users into downloading what appears to be legitimate software. Once executed, the malware operates as a stealer, designed to extract sensitive information from infected systems.

The discovery highlights a growing trend where cybercriminals exploit the trust users place in well-known applications, particularly targeting professionals and content creators who frequently rely on tools like Zoom for meetings, Slack for team communication, and StreamYard for live streaming. By masquerading as trusted software, the malware bypasses casual scrutiny, increasing the likelihood of successful infection.

Moonlock’s analysis indicates that Sonoma is specifically engineered to harvest data such as login credentials, session tokens, and potentially financial information—posing a significant risk to creators who manage multiple online accounts, monetization platforms, and client data through these apps. The malware’s focus on macOS reflects the platform’s rising popularity among creative professionals, making it an increasingly attractive target.

Users are advised to download software only from official websites or verified app stores, avoid third-party download portals, and enable security features like Gatekeeper and XProtect. Keeping systems updated and using trusted antivirus solutions can further reduce risk. As of September 21, 2026, Moonlock continues to monitor the threat and recommends vigilance when installing or updating any application, even those that appear familiar.

This incident underscores the importance of digital hygiene for creators, whose workflows depend heavily on the very tools being weaponized by attackers. Verifying file signatures, checking developer authenticity, and remaining skeptical of unsolicited download links are essential steps in defending against such evolving threats.

Join the conversation

Load Facebook comments to read and reply using your Facebook account.

Join the conversation

Load Facebook comments to read and reply using your Facebook account.