A new malware discovered on Apple’s macOS — tied to the North Korean hacking group Lazarus — has reportedly targeted blockchain engineers of a cryptocurrency exchange platform.

The macOS malware “KandyKorn” is a stealthy backdoor capable of data retrieval, directory listing, file upload/download, secure deletion, process termination, and command execution, according to an analysis by Elastic Security Labs.

MacOS malweare (REF7001) execution flow. Source: elastic.co

The above flowchart explains the steps taken by the malware to infect and hijack users’ computers. Initially, the attackers spread Python-based modules via Discord channels by impersonating members of the community.

The social engineering attacks trick community members into downloading a malicious ZIP archive named ‘Cross-platform Bridges.zip’ — imitating an arbitrage bot designed for automated profit generation. However, the file imports 13 malicious modules that work together to steal and manipulate information. The report read:

“We observed the threat actor adopting a technique we have not previously seen them use to achieve persistence on macOS, known as execution flow hijacking.”

The cryptocurrency sector remains a primary target for Lazarus, primarily motivated by financial gain rather than espionage, their other main operational focus.

The existence of KandyKorn underscores that macOS is well within Lazarus’ targeting range, showcasing the threat group’s remarkable ability to craft sophisticated and inconspicuous malware tailored for Apple computers.

Related: Onyx Protocol exploiter begins siphoning $2.1M loot on Tornado Cash

A recent exploit on Unibot, a popular Telegram bot used to snipe trades on the decentralized exchange Uniswap, crashed the token’s price by 40% in one hour.

Blockchain analytics firm Scopescan alerted Unibot users about an ongoing hack, which was later confirmed by an official source:

“We experienced a token approval exploit from our new router and have paused our router to contain the issue.”

Unibot committed to compensating all users who lost funds due to the contract exploit.

Magazine: Slumdog billionaire 2: ‘Top 10… brings no satisfaction’ says Polygon’s Sandeep Nailwal

Read More: World News | Entertainment News | Celeb News
Cointelegraph

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like

Democratic challenger to crypto-friendly senator’s seat is interested in space

Morgan Harper, a former senior advisor at the Consumer Financial Protection Bureau,…

Pentagon contracts with Inca Digital for a security-focused digital asset mapping tool

Digital asset data analytics company Inca Digital will study the implications of…

DJ 3LAU causes a stir after opting out of Friend.tech over regulatory risks

Popular DJ and crypto investor 3LAU (Justin Blau) has caused a stir…

Bitcoin mining update: Stocks cool off, miners send BTC to exchanges to prep for halving

In July, Bitcoin mining stocks continued their positive 2023 run, with the top…