logo

North Korean hackers use new macOS malware against crypto firms

ID: c198946d-4adc-5e94-abc5-d7eb5c79a469

STIX ID: report--c198946d-4adc-5e94-abc5-d7eb5c79a469

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-11-07

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

BlueNoroff's 'Hidden Risk' campaign targets crypto-focused macOS users with a notarized dropper app that displays a decoy PDF while installing a second-stage Mach-O backdoor ('growth'); the attackers bypass Gatekeeper using valid Apple developer credentials, override App Transport Security in Info.plist to fetch payloads, and establish persistence by modifying the user's .zshenv (plus a hidden touch file), evading macOS 13+ LaunchAgent alerts — the campaign has been active for roughly 12 months and includes observable IOCs such as attacker-controlled domains and the Apple Developer ID used.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.