By using this site, you agree privacy policies
Accept
Geek RoomGeek RoomGeek Room
  • Home
  • Tech
    TechShow More
    Split Technology Park welcomes first tenants: 26 MPSs and 6 startups
    October 31, 2024
    INNVEST Summit 2024: A premier event for innovation and economic competitiveness in the Western Balkans
    October 31, 2024
    Diaspora 4 Innovation: Kick-off event launches a new era for Albanian higher education
    October 31, 2024
    AI for good: Generative AI – Tirana chapter empowers Albanian Youth in tech innovation
    October 29, 2024
    Business Angel Summit 2024: Pioneering Investment and Startup Growth in Sarajevo
    October 29, 2024
  • Mobile
    MobileShow More
    Xiaomi 15 and 15 Pro set to launch on October 29: Official renders released
    October 24, 2024
    Dangerous virus infects millions of mobile phones through popular apps
    October 3, 2024
    The new iPhone 16 arrives in Croatia with a steep price tag
    September 26, 2024
    Beware of these phone numbers: Block them immediately to avoid scams
    September 11, 2024
    Beyond the brand: What really matters when buying a mobile phone
    September 5, 2024
  • Apps
    AppsShow More
    Shoppable widget by EmbedSocial: Revolutionizing E-commerce with authentic shopper content
    October 31, 2024
    Intel prevails in long-running legal battle against €1 billion EU fine
    October 31, 2024
    New definition of open source artificial intelligence released by OSI
    October 29, 2024
    CaSys introduces “Pay by Link” payment service for SMEs in Macedonia
    October 24, 2024
    Kickstarter surpasses $8 billion in donations across all projects
    October 17, 2024
  • Science
    ScienceShow More
    Sofia Tech Park: A thriving innovation hub for Southeast Europe
    October 29, 2024
    Breakthrough in prostate cancer treatment: Croatian scientists develop Vini, a tool to predict effective drug combinations
    October 24, 2024
    Digital Realty partners with Ecolab to pilot AI-powered water conservation solution
    October 24, 2024
    Sofia Tech Park to host the Southeast European Innovators Challenge Conference
    October 11, 2024
    ACG accelerates European growth with major expansion in Croatia
    October 9, 2024
  • Gaming
    GamingShow More
    “Windblown” – The new game from the creators of Dead Cells
    October 24, 2024
    Kraken Empire’s Journey and the creative brilliance of Toy Tactics
    October 21, 2024
    Serbian game studio Tricoman set to make a mark with their new RPG ‘Godforged’ on Steam
    October 16, 2024
    Release the demon with Kill Knight: A phenomenal combat experience with untapped potential
    October 14, 2024
    Nordeus launches new football game “Top Goal: Football Champion” in Serbia
    October 9, 2024
  • Cars
    CarsShow More
    Serbia signs strategic agreement with Hyundai Engineering for 1 GW of Solar Power
    October 16, 2024
    Stara Zagora: Poised to lead Bulgaria’s automotive revolution
    October 15, 2024
    Dacia unveils new Bigster: The flagship model for the C-SUV segment
    October 9, 2024
    Kineton Albania: Pioneering innovation in the automotive industry
    October 8, 2024
    Albania’s vehicle numbers surge in 2024: 73% of registered cars are over 15 years old
    August 20, 2024
  • Entertainment
    EntertainmentShow More
    Where are Generation Z’s famous tech entrepreneurs?
    October 29, 2024
    AllWeb offers special discounts for startups: A unique opportunity for networking and growth
    October 23, 2024
    Montenegro census reveals no ethnic majority, Montenegrins and Serbs nearly equal
    October 16, 2024
    “Primordial Passion” is the first luxury Albanian watch valued at €1.4 million by Argjendari Pirro
    October 15, 2024
    Albania takes the stage at BIG event Paris: Culture and innovation as economic drivers
    October 12, 2024
Search
Reading: North Korean hackers target crypto experts using macOS malware
Notification Show More
Aa
Geek RoomGeek Room
Aa
  • Tech
  • Mobile
  • Apps
  • Science
  • Gaming
  • Cars
  • Entertainment
Search
  • Home
  • Tech
  • Mobile
  • Apps
  • Science
  • Gaming
  • Cars
  • Entertainment
Geek Room > Blog > Tech > North Korean hackers target crypto experts using macOS malware
Tech

North Korean hackers target crypto experts using macOS malware

Last updated: 2023/11/02 at 1:37 PM
Share
4 Min Read

State-sponsored threat actors from the Democratic People’s Republic of Korea (DPRK) have been discovered targeting blockchain engineers associated with an undisclosed cryptocurrency exchange platform. This operation, which was initiated in April 2023, involved a novel macOS malware known as KANDYKORN.

Researchers at Elastic Security Labs have linked this activity to the infamous Lazarus Group, an adversarial collective with a history of cyber espionage and financial crimes. The threat actors used a Python application to lure blockchain engineers, gaining initial access to their environment. This intrusion consisted of multiple intricate stages, each employing sophisticated defence evasion techniques.

What sets this campaign apart is the attackers’ use of social engineering to trick victims on a public Discord server. They impersonated blockchain engineers and enticed their targets to download and execute a ZIP archive containing malicious code. The victims believed they were installing an arbitrage bot, a tool used to profit from cryptocurrency rate differences between platforms. However, this seemingly benign software download paved the way for the delivery of KANDYKORN, a sophisticated macOS malware.

KANDYKORN is an advanced implant with various capabilities, including monitoring, interaction, and evasion of detection. It employs reflective loading, a method of execution that can potentially bypass security measures.

The malware campaign begins with a Python script named “watcher.py,” which retrieves another Python script, “testSpeed.py,” hosted on Google Drive. This initial dropper then fetches an additional Python file, “FinderTools,” from a Google Drive URL. FinderTools also acts as a dropper, downloading and executing a hidden second-stage payload known as SUGARLOADER.

SUGARLOADER connects to a remote server to retrieve KANDYKORN and executes it directly in memory. It also launches a Swift-based self-signed binary called HLOADER, which masquerades as the legitimate Discord application and executes SUGARLOADER to establish persistence through execution flow hijacking.

KANDYKORN, the final-stage payload, is a comprehensive memory-resident Remote Access Trojan (RAT). It has built-in capabilities for file enumeration, running additional malware, data exfiltration, process termination, and executing arbitrary commands.

The DPRK, specifically the Lazarus Group, continues to target crypto-industry businesses, aiming to steal cryptocurrency to circumvent international sanctions that restrict their economic growth.

In a related development, the S2W Threat Analysis team has identified an updated version of an Android spyware called FastViewer, used by a North Korean threat cluster known as Kimsuky (also known as APT43), a sister hacking outfit of the Lazarus Group. FastViewer, first documented in October 2022, exploits Android’s accessibility services to covertly harvest sensitive data from compromised devices. It is typically disguised as benign security or e-commerce apps, distributed through phishing or smishing campaigns. The malware also downloads a second-stage malware called FastSpy for data gathering and exfiltration.

This new variant integrates FastSpy’s functionality directly into FastViewer, eliminating the need to download additional malware. However, there have been no reported cases of this variant being distributed in the wild.

As cybersecurity threats continue to evolve, organizations and individuals in the cryptocurrency and mobile device sectors need to remain vigilant and employ robust security measures to protect their assets and data.

You Might Also Like

Split Technology Park welcomes first tenants: 26 MPSs and 6 startups

INNVEST Summit 2024: A premier event for innovation and economic competitiveness in the Western Balkans

Shoppable widget by EmbedSocial: Revolutionizing E-commerce with authentic shopper content

Intel prevails in long-running legal battle against €1 billion EU fine

Diaspora 4 Innovation: Kick-off event launches a new era for Albanian higher education

Share This Article
Facebook Whatsapp Whatsapp Copy Link
Previous Article Meta, the parent company of Facebook, faces a European Union ban on personalized advertising
Next Article Historic global agreement on AI safety: World leaders convene at UK Summit

Social networks

Instagram Follow

Latest news

Split Technology Park welcomes first tenants: 26 MPSs and 6 startups
Tech October 31, 2024
INNVEST Summit 2024: A premier event for innovation and economic competitiveness in the Western Balkans
Tech October 31, 2024
Shoppable widget by EmbedSocial: Revolutionizing E-commerce with authentic shopper content
Apps October 31, 2024
Intel prevails in long-running legal battle against €1 billion EU fine
Apps October 31, 2024

Related articles

Tech

Split Technology Park welcomes first tenants: 26 MPSs and 6 startups

October 31, 2024
Tech

INNVEST Summit 2024: A premier event for innovation and economic competitiveness in the Western Balkans

October 31, 2024
Apps

Shoppable widget by EmbedSocial: Revolutionizing E-commerce with authentic shopper content

October 31, 2024
Apps

Intel prevails in long-running legal battle against €1 billion EU fine

October 31, 2024

About us

Geek Room is dedicated to technology and its enthusiasts through real-time information and videos about the latest innovations. Connect with our staff via email at: [email protected]
For cooperation opportunities, write to us at: [email protected]

Find us:

© 2023 Geekroom All Rights Reserved. Developed by MIMS
adbanner
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Lost your password?