New MacOS Backdoor Threat from North Korean Hackers

New MacOS Backdoor Threat from North Korean Hackers

A new macOS backdoor threat called SpectralBlur has been discovered from North Korean hackers. This malicious software bears similarities to KANDYKORN, an advanced implant that functions as a remote access trojan capable of taking control of a compromised host. Additionally, it is noted that KANDYKORN is associated with a backdoor named RustBucket, orchestrated by BlueNoroff (also known as TA444), and a subsequent payload named ObjCShellz. In recent months, observations have revealed that threat actors have combined different parts of these two infection chains and utilized RustBucket droppers to deliver KANDYKORN. These findings are considered an indication of North Korean threat actors’ increasing interest in infiltrating macOS, particularly to target high-value entities in the cryptocurrency and blockchain sectors.

Mert Doğukan is an experienced C-level executive, CISO, specialized in information security and risk management. With strong leadership qualities and strategic vision, he plays a crucial role in protecting and ensuring the security of the company's information assets. He demonstrates top-level performance in developing, implementing, and auditing corporate-level information security strategies. Additionally, he closely monitors technological advancements to continuously update and enhance the company's cybersecurity infrastructure.

Related Posts