BlueNoroff used macOS malware with novel persistence
Essential information
- Published
- 08/11/2024 00:02
- Modified
- 08/11/2024 10:22
- Tags
- 2024-11-08 apt cryptocurrency growth lessonone macos north korea persistence phishing
- Related entities
- 1 intrusion sets (apt), 6 techniques (mitre), 2 malware, 1 others
Description
SentinelLabs researchers identified a North Korea-linked threat actor targeting crypto businesses with new macOS malware as part of a campaign called 'Hidden Risk'. The attackers, linked to BlueNoroff, used fake cryptocurrency news emails and a malicious app disguised as a PDF to deliver multi-stage malware. The malware uses a novel persistence technique exploiting the Zsh configuration file to bypass macOS security notifications. The campaign has been active since July 2024 and shows BlueNoroff's continued focus on targeting the crypto and Web3 sectors with evolving tactics.