TodoSwift: North Korean Cybercriminals Use Bitcoin Lure to Spread macOS Malware
ID: 6e779f98-4a0b-51d6-bbee-1b4e17df9549
STIX ID: report--6e779f98-4a0b-51d6-bbee-1b4e17df9549
Feed Name: securityonline.info
Threat Score
### Executive summary: The report describes TodoSwift, a signed macOS dropper discovered on VirusTotal that poses as a Bitcoin PDF to lure users while silently downloading and launching a second-stage payload via Google Drive; analysis links the sample to DPRK-aligned BlueNoroff and highlights its Swift/SwiftUI GUI, use of Google Drive for payload delivery, and C2 passed as a launch argument, with stage-2 capabilities still under investigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
