North Korea Debuts 'SpectralBlur' Malware Amid macOS Onslaught
ID: 97c70c93-90cb-5a85-983a-3388bba97336
STIX ID: report--97c70c93-90cb-5a85-983a-3388bba97336
Feed Name: Dark Reading
Date Published: 2024-01-05
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
TA444, a North Korean state-backed APT, debuted a new macOS backdoor named SpectralBlur in August. Proofpoint analysis shows SpectralBlur provides post-exploitation capabilities (file transfer, remote shell, config updates, file deletion) and shares code/strings with other macOS malware like KandyKorn, linking it to phishing campaigns and underscoring an embedded malware development capability within TA444 targeting macOS users, including cryptocurrency-related targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
