North Korean Hackers Use Weaponized Calendly and Google Meet Links to Deliver Malware
ID: 6e016dc5-5ab3-5458-b196-8dd2f768bb6c
STIX ID: report--6e016dc5-5ab3-5458-b196-8dd2f768bb6c
Feed Name: Cyber Press
TA444 (aka BlueNoroff and other aliases) ran a sophisticated campaign against a cryptocurrency organization using Calendly/Google Meet lures that redirected victims to a spoofed Zoom domain, deepfake avatars in group calls, and an AppleScript initial dropper that installed a multi-stage macOS malware suite (Nim persistent loader, Go backdoor "Root Troy V4/remoted", process injection loader, Objective-C keylogger/screen recorder, and a crypto-focused infostealer). The operation employed Rosetta 2 installation checks for Apple Silicon compatibility, encrypted configs, anti-forensics, and multiple C2 domains masquerading as legitimate services; the report includes file hashes, malicious domains, and mitigation recommendations such as EDR, user education, and verification of meeting invites and external plugins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
