North Korean Hackers Target Crypto Firms with Hidden Risk Malware on macOS
Nov 07, 2024
Cryptocurrency / Malware
 A threat actor with ties to the Democratic People's Republic of Korea (DPRK) has been observed targeting cryptocurrency-related businesses with a multi-stage malware capable of infecting Apple macOS devices .  Cybersecurity company SentinelOne, which dubbed the campaign Hidden Risk , attributed it with high confidence to BlueNoroff, which has been previously linked to malware families such as RustBucket , KANDYKORN , ObjCShellz , RustDoor  (aka Thiefbucket ), and TodoSwift .  The activity "uses emails propagating fake news about cryptocurrency trends to infect targets via a malicious application disguised as a PDF file," researchers Raffaele Sabato, Phil Stokes, and Tom Hegel said  in a report shared with The Hacker News.  "The campaign likely began as early as July 2024 and uses email and PDF lures with fake news headlines or stories about crypto-related topics."   As revealed  by the U.S. Federal Bureau of Investigation (FBI) in a September 2024 advisory, the...