• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
n. korean hackers 'mixing' macos malware tactics to evade detection

N. Korean Hackers ‘Mixing’ macOS Malware Tactics to Evade Detection

You are here: Home / General Cyber Security News / N. Korean Hackers ‘Mixing’ macOS Malware Tactics to Evade Detection
November 28, 2023

The North Korean risk actors at the rear of macOS malware strains such as RustBucket and KANDYKORN have been noticed “mixing and matching” diverse things of the two disparate attack chains, leveraging RustBucket droppers to supply KANDYKORN.

The findings arrive from cybersecurity firm SentinelOne, which also tied a third macOS-certain malware termed ObjCShellz to the RustBucket marketing campaign.

RustBucket refers to an exercise cluster joined to the Lazarus Team in which a backdoored version of a PDF reader application, dubbed SwiftLoader, is utilized as a conduit to load a subsequent-phase malware composed in Rust upon viewing a specifically crafted lure document.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Cybersecurity

The KANDYKORN campaign, on the other hand, refers to a destructive cyber procedure in which blockchain engineers of an unnamed crypto exchange platform ended up specific via Discord to initiate a advanced multi-phase attack sequence that led to the deployment of the eponymous full-highlighted memory resident remote accessibility trojan.

The third piece of the attack puzzle is ObjCShellz, which Jamf Menace Labs discovered before this month as a afterwards-stage payload that functions as a distant shell that executes shell commands sent from the attacker server.

macOS Malware

Even further evaluation of these strategies by SentinelOne has now shown that the Lazarus Team is utilizing SwiftLoader to distribute KANDYKORN, corroborating a the latest report from Google-owned Mandiant about how diverse hacker groups from North Korea are more and more borrowing each individual other’s strategies and tools.

“The DPRK’s cyber landscape has evolved to a streamlined firm with shared tooling and focusing on attempts,” Mandiant observed. “This adaptable approach to tasking makes it hard for defenders to monitor, attribute, and thwart malicious things to do, though enabling this now collaborative adversary to move stealthily with bigger velocity and adaptability.”

Cybersecurity

This involves the use of new variants of the SwiftLoader stager that purports to be an executable named EdoneViewer but, in reality, contacts an actor-controlled domain to likely retrieve the KANDYKORN RAT based mostly on overlaps in infrastructure and the ways utilized.

The disclosure will come as the AhnLab Security Unexpected emergency Reaction Heart (ASEC) implicated Andariel – a subgroup in just Lazarus – to cyber attacks exploiting a security flaw in Apache ActiveMQ (CVE-2023-46604, CVSS score: 10.) to put in NukeSped and TigerRAT backdoors.

Observed this posting exciting? Abide by us on Twitter  and LinkedIn to read additional unique information we post.


Some pieces of this post are sourced from:
thehackernews.com

Previous Post: «how to handle retail saas security on cyber monday How to Handle Retail SaaS Security on Cyber Monday
Next Post: Hackers Can Exploit ‘Forced Authentication’ to Steal Windows NTLM Tokens hackers can exploit 'forced authentication' to steal windows ntlm tokens»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.