Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Intelligence View
⚡ tsecurity.de Intelligence

SpectralBlur: The New macOS Backdoor Linked to North Korean Threat Actors

SpectralBlur: The New macOS Backdoor Linked to North Korean Threat Actors Post Views:…

0
↗ Quelle (blackhatethicalhacking.com)
Reagiere als Erste:r — dein Feedback zählt!

























SpectralBlur: The New macOS Backdoor Linked to North Korean Threat Actors



















































Join our Patreon Channel and Gain access to 70+ Exclusive Walkthrough Videos.







Patreon

















Reading Time: 3 Minutes























Cybersecurity researchers have uncovered a new macOS backdoor named SpectralBlur, which shares characteristics with a known malware family associated with North Korean threat actors.

 

According to security researcher Greg Lesnewich, SpectralBlur is a moderately capable backdoor that can perform various functions, such as uploading/downloading files, running a shell, updating its configuration, and executing commands from the command-and-control server.

 

The similarities between SpectralBlur and KANDYKORN, an advanced implant functioning as a remote access trojan, have raised concerns about the potential overlap between the two malware families. Notably, the KANDYKORN activity intersects with a campaign attributed to the Lazarus sub-group known as BlueNoroff, culminating in the deployment of a backdoor called RustBucket and a late-stage payload named ObjCShellz.











See Also: So, you want to be a hacker?

Offensive Security, Bug Bounty Courses



















Discover your weakest link. Be proactive, not reactive. Cybercriminals need just one flaw to strike.















Recent observations indicate that the threat actor has been combining elements from these two infection chains, utilizing RustBucket droppers to deliver KANDYKORN. This trend suggests that North Korean threat actors are increasingly targeting macOS systems, particularly those within the cryptocurrency and blockchain industries.

 

Security researcher Patrick Wardle provided additional insights into SpectralBlur, noting that the Mach-O binary was uploaded to the VirusTotal malware scanning service from Colombia in August 2023. The malware’s attempts to hinder analysis and evade detection, such as using grantpt to set up a pseudo-terminal and execute shell commands from the C2 server, make it stand out.



























































































































































































The discovery of SpectralBlur adds to the growing list of macOS-targeting malware families, including ransomware, information stealers, remote access trojans, and nation-state-backed malware. With the increasing popularity of macOS, especially in enterprise environments, experts anticipate a surge in new macOS malware in 2024.








































































































































































Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?


If you want to express your idea in an article contact us here for a quote: [email protected]







Source: thehackernews.com


Source Link







Merch


















Offensive Security & Ethical Hacking Course


Begin the learning curve of hacking now!





Information Security Solutions


Find out how Pentesting Services can help you.




Join our Community






The post SpectralBlur: The New macOS Backdoor Linked to North Korean Threat Actors first appeared on Black Hat Ethical Hacking.
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten SpectralBlur: The New macOS Backdoor Linked to North Korean Threat Actors

Thematisch verwandte Begriffe: SpectralBlur, macOS, Backdoor, Linked · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-17636 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick