logo

“Can You Hear Me?” BlueNoroff Hackers Use Fake Audio Glitch to Breach macOS

ID: 161191e8-d290-5512-9be9-e9a323c9cbef

STIX ID: report--161191e8-d290-5512-9be9-e9a323c9cbef

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-02-05

Date Updated: 2026-04-23

Author: Ddos

...
...

Daylight Security reports a BlueNoroff (Lazarus subgroup) campaign that lures cryptocurrency and financial professionals from messaging apps into Microsoft Teams calls, where attackers feign audio issues to coerce victims into pasting terminal commands. The commands download a macOS executable placed at /Library/Caches/com.apple.sys.receipt which the actor makes executable and ad-hoc signs; the observed payload performs credential theft by copying the user Keychain and employs additional hidden components for persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.