we've observed 8 new pieces of macOS malware from implants to infostealers! and they're actually good (for once)!
www.huntress.com/blog/inside-...
we've observed 8 new pieces of macOS malware from implants to infostealers! and they're actually good (for once)!
www.huntress.com/blog/inside-...
🇰🇵 BlueNoroff Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel Persistence
www.sentinelone.com/labs/bluenor...
🇰🇵 BlueNoroff Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel Persistence
www.sentinelone.com/labs/bluenor...
www.technadu.com/bluenoroff-a...
What do you think about APTs weaponizing video calls and recruitment platforms?
#CyberSecurity #BlueNoroff #GhostCall #GhostHire #APT #Web3Security #Infosec
www.technadu.com/bluenoroff-a...
What do you think about APTs weaponizing video calls and recruitment platforms?
#CyberSecurity #BlueNoroff #GhostCall #GhostHire #APT #Web3Security #Infosec
Deepfake Zoom calls. AppleScript lures. Rosetta 2 abuse.
Plenty of custom malware: Nim backdoor, Go infostealer, Obj-C keylogger, and more!
Amazing write-up by @re.wtf , @stuartjash.bsky.social and Jonathan Semon 🔥
🔗 www.huntress.com/blog/inside-...
(Or WORSE, calling Contagious Interview “Lazarus”. Or Kimsuky “Lazarus”. Or IT Workers “Lazarus”. I will literally SCREAM 🫠)
(Or WORSE, calling Contagious Interview “Lazarus”. Or Kimsuky “Lazarus”. Or IT Workers “Lazarus”. I will literally SCREAM 🫠)
Hate to break it to ‘em, but that ain’t how we roll. 😆
Hate to break it to ‘em, but that ain’t how we roll. 😆
github.com/tayvano/laza...
github.com/tayvano/laza...
Deepfake Zoom calls. AppleScript lures. Rosetta 2 abuse.
Plenty of custom malware: Nim backdoor, Go infostealer, Obj-C keylogger, and more!
Amazing write-up by @re.wtf , @stuartjash.bsky.social and Jonathan Semon 🔥
🔗 www.huntress.com/blog/inside-...
Deepfake Zoom calls. AppleScript lures. Rosetta 2 abuse.
Plenty of custom malware: Nim backdoor, Go infostealer, Obj-C keylogger, and more!
Amazing write-up by @re.wtf , @stuartjash.bsky.social and Jonathan Semon 🔥
🔗 www.huntress.com/blog/inside-...
💥Learn hunting techniques
💥Leverage new Validin features and data
💥Full, unredacted indicator list (domains, IPs, hashes)
www.validin.com/blog/zooming...
💥Learn hunting techniques
💥Leverage new Validin features and data
💥Full, unredacted indicator list (domains, IPs, hashes)
www.validin.com/blog/zooming...
paragraph.com/@investigati...
paragraph.com/@investigati...
--UK Financial Conduct Authority gave Palantir access to sensitive data,
--Hackers stole $23m in Ether from DeFi protocol Resolv Labs,
--Bluenoroff group stole 18.5k purchase records from gift card platform Bitrefill, 2/5
--UK Financial Conduct Authority gave Palantir access to sensitive data,
--Hackers stole $23m in Ether from DeFi protocol Resolv Labs,
--Bluenoroff group stole 18.5k purchase records from gift card platform Bitrefill, 2/5
YARA looks for the header used in a .SCPT file used by BlueNoroff (DPRK) to target MacOS systems.
Script is delivered to victims disguised as a Zoom meeting launcher.
e.g. a7c7d75c33aa809c231f1b22521ae680248986c980b45aa0881e19c19b7b1892
Rule at end
1/3
YARA looks for the header used in a .SCPT file used by BlueNoroff (DPRK) to target MacOS systems.
Script is delivered to victims disguised as a Zoom meeting launcher.
e.g. a7c7d75c33aa809c231f1b22521ae680248986c980b45aa0881e19c19b7b1892
Rule at end
1/3
thehackernews.com/2023/11/n-ko...
#cybersecurity #informationsecurity
thehackernews.com/2023/11/n-ko...
#cybersecurity #informationsecurity