New BlueNoroff loader for macOS

2023-12-05 • Kaspersky •

https://securelist.com/bluenoroff-new-macos-malware/111290/

Thumbnail for New BlueNoroff loader for macOS

Kaspersky analyzed a new macOS loader likely linked to BlueNoroff's RustBucket campaign against cryptocurrency and financial targets. The ZIP archive contained a fake PDF theme, "Crypto-assets and their risks for financial stability," and a signed Swift app named EdoneViewer that decrypted an AppleScript payload. The script opened a benign PDF as a decoy, posted to the C2 server, saved a hidden /Users/Shared/.pw payload, and executed it with the C2 address as an argument. The .pw Trojan collected startup time, OS installation date, and running process data every minute, then waited for commands to execute a downloaded file, delete itself, or keep polling.

Indicators of Compromise

Type Value First Seen Last Seen
HASH c7f4aa77be7f7afe9d0665d3e705dbf… 2023-11-27 2024-12-27
HASH c9a7b42c7b29ca948160f95f017e9e9… 2023-11-27 2024-12-27
HASH 4f6690b82ca4b1f5735386729c4a041… 2023-12-05 2023-12-15
HASH da96876f9535e3946aff3875c5e5c05… 2023-12-05 2023-12-05
HASH b0b1730ecbc7ff4505142c49f1295e6… 2023-12-05 2023-12-05
HASH 7afc9d01a62f03a2de9637936d4afe6… 2023-12-05 2023-12-05
URL http://on-global.xyz 2023-12-05 2023-12-05
URL http://on-global.xyz/Of56cYsfVV… 2023-12-05 2023-12-05
URL http://on-global.xyz/Ov56cYsfVV… 2023-12-05 2023-12-05
HASH 47b8b4d55d75505d617e53afcb6c32d… 2023-11-27 2023-12-05
HASH 36001b8b9e05935756fa7525dd49d91… 2023-11-27 2023-12-05
HASH c556baaac706191ce75c9263b349242… 2023-11-27 2023-12-05
DOMAIN on-global.xyz 2023-11-27 2023-12-05

Related Actors

Related Reports

« Back