logo

Inside the BlueNoroff Web3 macOS Intrusion Analysis

ID: 69866533-413e-5834-a02b-4988da0246d1

STIX ID: report--69866533-413e-5834-a02b-4988da0246d1

Feed Name: Huntress Blog

Threat Score
90/100

Date Published: 2025-06-18

Date Updated: 2026-04-28

...
...

On June 11, 2025 Huntress investigated a targeted macOS intrusion against a cryptocurrency foundation attributed with high confidence to DPRK APT subgroup TA444 (BlueNoroff). The attackers used meeting-based social engineering (fake Zoom link and deepfakes) to deliver an AppleScript that installed multiple implants, including a Nim persistent loader (“Telegram 2”), a Go backdoor (“Root Troy V4”), an Objective-C keylogger/screen recorder (XScreen/keyboardd), and a Go infostealer focused on crypto wallets (CryptoBot). The report provides full technical analysis of persistence, process-injection and decryption mechanisms, active C2 domains, and comprehensive IOCs (file SHA256s and infrastructure hosts) with remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.