21 August 2024

North Korean hackers BlueNoroff add new macOS malware TodoSwift to their arsenal


North Korean hackers BlueNoroff add new macOS malware TodoSwift to their arsenal

A new strain of macOS malware has been discovered believed to be the work of a North Korean state-backed APT group known as BlueNoroff. Dubbed ‘TodoSwift’ by Kandji researchers, the malware was first discovered when a signed file named TodoTasks was uploaded to VirusTotal on July 24, 2024.

TodoSwift shares several behavioral patterns with other known malware linked to North Korea, particularly those associated with the BlueNoroff group, including KANDYKORN and RustBucket.

RustBucket, first reported in July 2023, is an AppleScript-based backdoor that can fetch additional malicious payloads from a command-and-control (C2) server. Similarly, KANDYKORN, discovered last year, was used in a sophisticated cyber attack targeting blockchain engineers at an unnamed cryptocurrency exchange platform. The malicious tool can access and exfiltrate data, terminate arbitrary processes, and execute commands on the infected system.

A common thread connecting the above mentioned malware families is the use of linkpc[.]net domains for command-and-control (C2) purposes, a tactic also employed by BlueNoroff’s TodoSwift. The new malware is distributed through a dropper component masquerading as a legitimate application called TodoTasks. This dropper is a GUI application built with SwiftUI, designed to display a benign Bitcoin-related PDF document while secretly downloading and executing a second-stage binary—a technique that is similar to the one employed by RustBucket.

The PDF used in this attack is hosted on Google Drive and appears harmless, but the actual malicious payload is fetched from an actor-controlled domain.

Researchers are still analyzing the specifics of the downloaded binary, but the method of using a Google Drive URL and passing the C2 URL as a launch argument to the second-stage binary aligns with tactics previously seen in other North Korea-linked malware targeting macOS systems.


Back to the list

Latest Posts

What is Vulnerability Management? A Beginner's Guide

What is Vulnerability Management? A Beginner's Guide

In this article will try to cover basics of vulnerability management process and why it is important to every company.
11 September 2024
Cyber Security Week in Review: September 6, 2024

Cyber Security Week in Review: September 6, 2024

In brief: the US charges Russian GRU hackers for attacks on Ukraine, Apache, Cisco, Zyxel patch high-risk flaws, Google fixes Android zero-day, and more.
6 September 2024
Threat actors using MacroPack Red Team framework to deploy Brute Ratel, Havoc and PhantomCore

Threat actors using MacroPack Red Team framework to deploy Brute Ratel, Havoc and PhantomCore

Some of the documents appeared to be part of legitimate Red Team exercises, while other were intended for malicious purposes.
5 September 2024