Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » North Korean hackers have targeted macOS with malware embedded in Flutter
Global Security

North Korean hackers have targeted macOS with malware embedded in Flutter

AdminBy AdminNovember 12, 2024No Comments3 Mins Read
macOS Malware
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


November 12, 2024Ravi LakshmananMalware / Application Security

macOS malware

Threat actors associated with the Democratic People’s Republic of Korea (DPRK, aka North Korea) were found to be embedding malware into Flutter apps, marking the first time an adversary has adopted this tactic to infect Apple macOS devices.

Jamf Threat Labs, which made the discovery based on artifacts uploaded to the VirusTotal platform earlier this month, said the apps created by Flutter are part of a broader operation that includes malware written in Golang and Python.

It is currently unknown how these samples are being distributed to victims, whether they have been used against any targets, or whether attackers are switching to a new delivery method. At the same time, it is known that North Korean threat actors are involved in this extensive social engineering efforts targeting employees of cryptocurrency and decentralized financial companies.

Cyber ​​security

“We suspect that these particular examples are test cases,” Jaron Bradley, director of Jamf Threat Labs, told The Hacker News. “Maybe they haven’t been distributed yet. It’s hard to say. But yes. The attacker’s social engineering techniques have worked very well in the past, and we suspect that they will continue to use these techniques.”

Jamf has not attributed the malicious activity to a specific hacking group linked to North Korea, but it is likely the work of a Lazarus subgroup known as BlueNoroff. This connection stems from an infrastructure overlap with malware called CANDY CORN and Hidden Risk Company recently allocated Sentinel One.

What sets the new malware apart is its use of Flutter, a cross-platform application development framework, to embed a core payload written in Dart under the guise of a full-featured Minesweeper game. The app is called “New Updates in Crypto Exchange (2024-08-28)”.

macOS malware

Moreover, the game looks like a clone of the base Flutter game for iOS publicly available on GitHub. Notably, the use of game-themed decoys has also been seen in conjunction with another North Korean hacking group tracked as Moonstone.

These applications have also been signed and notarized using the Apple Developer IDs of BALTIMORE JEWISH COUNCIL, INC. (3AKYHFR584) and FAIRBANKS CURLING CLUB INC. (6W69GC943U), suggesting that threat actors may be able to bypass Apple notarization process. The signatures have since been revoked by Apple.

Once launched, the malware sends a network request to a remote server (“mbupdate.linkpc(.)net”) and is configured to execute the AppleScript code received from the server, but not before it is written back.

Cyber ​​security

Jamf said it has also identified variants of the malware written in Go and Python, with the latter built using Py2App. The apps – called NewEra for Stablecoins and DeFi, CeFi (Protected).app and Runner.app – are equipped with similar capabilities to run any AppleScript payload received in the server’s HTTP response.

Recent developments are a sign that North Korean threat actors are actively developing malware using multiple programming languages ​​to infiltrate cryptocurrency companies.

“The malware discovered in the actor in recent years comes in many variants with frequently updated iterations,” Bradley said. “We suspect this is due to efforts to remain undetected and support malware that looks different with each release. In the case of Dart, we suspect this is because contributors have found that Flutter applications create a lot of obscurity due to their post-compile architecture.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025

Fedramp at starting speed: obtained lessons

June 18, 2025

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025

Fedramp at starting speed: obtained lessons

June 18, 2025

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025

Iran slows the Internet to prevent cyber -napades against the background of escalation of regional conflict

June 18, 2025

RCE Critical Error RCE Rate 9.9 CVSS in Backup and Replication

June 18, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.