North Korean hackers target IT Job Seekers With macOS Malware

Share post:

Security researchers at cybersecurity company ESET have uncovered the malicious activities of North Korean hackers targeting IT job seekers.

The gang, identified as the Lazarus group, uses a signed malicious executable program for macOS to imitate Coinbase. The name of the forged documents was “Coinbase _ online _ careers _ 2022 _ 07.” When launched, the malicious document displays a bait PDF and loads a malicious DLL that ultimately allows the threat actors to send commands to the infected device.

According to the researchers, the malicious software for Macs is compatible with both Intel and Apple Silicon, meaning that both old and new models were targeted by the malware campaign.

The new macOS malware has a downloader component that connects to another command and control (C2) server, although it stopped responding after an analysis by experts.

Lazarus, a notorious hacking gang from North Korea, is known for various forms of cyberattacks on U.S. organizations. Billions of dollars have already been extorted by the gang as it targets several organizations through phishing and other tactics.

The sources for this piece include an article in BleepingComputer.

SUBSCRIBE NOW

Related articles

Hashtag Trending for World Password Day, Thursday, May 2nd, 2024

Security firm Okta warns of an unprecendented password stuffing attack that is piggybacking on regular user’s mobile and...

Google Chrome’s new post-quantum cryptography causes connection issues

The latest update to Google Chrome, version 124, which integrates a new quantum-resistant encryption mechanism, has led to...

UK legislation bans weak passwords

Starting Monday, the UK will enforce new laws banning the sale of devices with weak default passwords such...

Massive Credential Stuffing attack exploits home devices

Okta, a leading authentication service, is raising alarms over a massive credential-stuffing attack that cleverly disguises fraudulent login...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways