logo

North Korea Debuts 'SpectralBlur' Malware Amid macOS Onslaught

ID: 97c70c93-90cb-5a85-983a-3388bba97336

STIX ID: report--97c70c93-90cb-5a85-983a-3388bba97336

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-01-05

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

TA444, a North Korean state-backed APT, debuted a new macOS backdoor named SpectralBlur in August. Proofpoint analysis shows SpectralBlur provides post-exploitation capabilities (file transfer, remote shell, config updates, file deletion) and shares code/strings with other macOS malware like KandyKorn, linking it to phishing campaigns and underscoring an embedded malware development capability within TA444 targeting macOS users, including cryptocurrency-related targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.