← All detection heuristics · RTF
critical
RTF_MACOS_ZSH_LOADER
What it means
Visible RTF text contains a base64/gzip shell loader executed with zsh.
Why it fires
The RTF body is not exploiting the RTF parser. Instead, it carries a visible shell command or embedded shell script that decodes a URL or gzip-compressed stage and executes it with zsh. The decoded stage is treated as malware when it retrieves and executes AppleScript via osascript, posts host/locale telemetry, or uses geofencing logic.
Other RTF heuristics
RTF_EQUATION_EDITOR RTF_OBJCLASS_EQUATION RTF_MZ_HEX RTF_DDEAUTO_REGSVR32_SCRIPTLET RTF_PACKAGE_AUTOLINK_DELIVERY RTF_OBJAUTLINK RTF_INCLUDE_REMOTE RTF_EXCESSIVE_HEX RTF_PACKAGE_OLE RTF_OBFUSCATION RTF_PHP_IRC_BOT_SOURCE RTF_OBJCLASS_PACKAGE RTF_REMOTE_TEMPLATE RTF_EXPLOIT_TEMPLATE_ARTIFACT RTF_OBJUPDATE_LOOSE_HEX_PAYLOAD RTF_OBJUPDATE RTF_PFRAGMENTS_RELATED RTF_OBJEMB RTF_WORD_COMPATIBILITY_PACKAGE RTF_OBJDATA RTF_OLEPRES_STREAM RTF_OLE10NATIVE_STREAM