logo

BlueNoroff Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel Persistence

Threat Score
90/100

Date Published: 2024-11-07

Date Updated: 2026-07-27

Author: Raffaele Sabato, Phil Stokes & Tom Hegel

...
...

SentinelLABS describes the "Hidden Risk" campaign, attributed with high confidence to DPRK-linked BlueNoroff, which targets cryptocurrency-related organizations using phishing emails that deliver a macOS dropper and a multi-stage backdoor ('growth'). The report details the infection chain (PDF lure → signed macOS app dropper → x86_64 backdoor), a novel persistent mechanism abusing ~/.zshenv to evade macOS notifications, C2 behavior and capabilities to fetch and execute payloads, associated network infrastructure, and extensive indicators of compromise (file hashes, IP addresses, and domains).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.