Analyzing DPRK's SpectralBlur

2024-01-04 Objective-see

https://objective-see.org/blog/blog_0x78.html

Thumbnail for Analyzing DPRK's SpectralBlur

Objective-See analyzes SpectralBlur, a DPRK-linked macOS backdoor previously described by Greg Lesnewich as related to TA444 and BLUENOROFF activity. The sample is an unsigned 64-bit Intel Mach-O seen as .macshare or mac.jpg, with VirusTotal telemetry showing submission in August 2023 and function names left intact. Static analysis shows configuration, socket, packet handling, xcrypt, and command routines for directory listing, upload and download, shell execution, file removal, restart, sleep, hibernate, and configuration changes. The post validates those capabilities through imported APIs and disassembly, including unlink for file removal and network/process APIs used by the command handlers.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 6f3e849ee0fe7a6453bd0408f0537fa… 2024-01-03 2024-12-13

Related Actors

Related Reports

« Back