logo

TodoSwift: North Korean Cybercriminals Use Bitcoin Lure to Spread macOS Malware

ID: 6e779f98-4a0b-51d6-bbee-1b4e17df9549

STIX ID: report--6e779f98-4a0b-51d6-bbee-1b4e17df9549

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2024-08-23

Date Updated: 2026-04-22

Author: do son

...
...

### Executive summary: The report describes TodoSwift, a signed macOS dropper discovered on VirusTotal that poses as a Bitcoin PDF to lure users while silently downloading and launching a second-stage payload via Google Drive; analysis links the sample to DPRK-aligned BlueNoroff and highlights its Swift/SwiftUI GUI, use of Google Drive for payload delivery, and C2 passed as a launch argument, with stage-2 capabilities still under investigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.