216.73.217.22

New threat targeting macOS discovered

· Published 13/11/2024 12:24 · Modified 13/11/2024 12:58

Export JSON

Essential information

Published
13/11/2024 12:24
Modified
13/11/2024 12:58
Tags
2024-11-13 applescript dprk flutter golang macos obfuscation python stage-one-payload
Related entities
1 intrusion sets (apt), 6 techniques (mitre)

Description

Jamf Threat Labs uncovered malware samples linked to North Korea, built using , which provides inherent . The malware, discovered in late October, includes Go, , and variants. The -built application presents a minesweeper game while making network requests to a known -associated domain. The malware executes code received from the server. Similar functionality was observed in Go and variants. The attackers may be testing new weaponization techniques, potentially attempting to bypass Apple's notarization process and antivirus detection. This marks the first instance of this actor using to target devices.

External references