logo

North Korean hackers create Flutter apps to bypass macOS security

ID: aafaf6ee-4780-54fc-a45e-827efe884baf

STIX ID: report--aafaf6ee-4780-54fc-a45e-827efe884baf

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-11-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Jamf Threat Labs discovered multiple notarized, signed macOS applications built with Flutter (and variants in Go/Python) that appear trojanized to execute AppleScript from a C2 and contact a DPRK-linked domain (mbupdate.linkpc.net); apps were named with cryptocurrency themes, likely indicating North Korean financial-motivated testing, and Apple has since revoked the developer signatures though operational use remains uncertain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.