North Korean hackers use new macOS malware against crypto firms
ID: c198946d-4adc-5e94-abc5-d7eb5c79a469
STIX ID: report--c198946d-4adc-5e94-abc5-d7eb5c79a469
Feed Name: Bleeping Computer
BlueNoroff's 'Hidden Risk' campaign targets crypto-focused macOS users with a notarized dropper app that displays a decoy PDF while installing a second-stage Mach-O backdoor ('growth'); the attackers bypass Gatekeeper using valid Apple developer credentials, override App Transport Security in Info.plist to fetch payloads, and establish persistence by modifying the user's .zshenv (plus a hidden touch file), evading macOS 13+ LaunchAgent alerts — the campaign has been active for roughly 12 months and includes observable IOCs such as attacker-controlled domains and the Apple Developer ID used.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
