Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » New macOS backdoor threat from North Korean hackers
    Cyber Security

    New macOS backdoor threat from North Korean hackers

    techempireBy techempire3 Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportJanuary 5, 2024Editorial DepartmentEndpoint Security/Malware

    SpectralBlur macOS backdoor

    Cybersecurity researchers have discovered a new Apple macOS backdoor called Spectral blur The malware overlaps with known malware families operated by North Korean threat actors.

    “SpectralBlur is a moderately functional backdoor that can upload/download files, execute a shell, update its configuration, delete files, hibernate or sleep based on commands issued from the computer. [command-and-control] server,” said security researcher Greg Lesnewich.

    The malware bears similarities to KANDYKORN (also known as SockRacket), an advanced implant that acts as a remote access Trojan capable of taking control of an infected host.

    Internet security

    Notably, the KANDYKORN campaign also intersected with another campaign orchestrated by the Lazarus subgroup BlueNoroff (also known as TA444), which ultimately deployed a backdoor named RustBucket and a post-production payload named ObjCShellz.

    In recent months, we have observed threat actors combining different parts of these two infection chains to leverage RustBucket droppers to spread KANDYKORN.

    The latest findings are another sign that North Korean threat actors are increasingly looking to macOS to infiltrate high-value targets, particularly within the cryptocurrency and blockchain industries.

    “TA444 continues to operate fast and furious in these new macOS malware families,” Lesnewich said.

    Security researcher Patrick Wardle shared additional insights into the inner workings of SpectralBlur, saying that the Mach-O binary was uploaded to the VirusTotal malware scanning service from Colombia in August 2023.

    The functional similarities between KANDYKORN and SpectralBlur raise the possibility that they may have been built by different developers with the same needs in mind.

    Internet security

    This malware is notable because it attempts to hinder analysis and evade detection when it uses grantpt to set up a pseudo-terminal and execute shell commands received from the C2 server.

    This revelation comes as a total of 21 new malware families were discovered targeting macOS systems in 2023, including ransomware, information stealers, remote access Trojans and state-sponsored malware. Malware families discovered in 2022 for 13.

    “As macOS continues to grow and become more popular (especially in the enterprise!), 2024 is sure to bring a lot of new macOS malware,” Wardle noted.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.