North Korean Threat Actors Deploy Flutter-Based Malware to Target macOS Users – Active IOCs

2024-11-13 Rewterz

https://www.rewterz.com/threat-advisory/north-korean-threat-actors-deploy-flutter-based-malware-to-target-macos-users-active-iocs

Thumbnail for North Korean Threat Actors Deploy Flutter-Based Malware to Target macOS Users – Active IOCs

North Korean threat actors are described as testing or deploying macOS malware embedded in Flutter applications, including a Minesweeper-themed lure named "New Updates in Crypto Exchange (2024-08-28)." The malware uses Dart payloads, compromised Apple developer IDs, and a C2 at mbupdate.linkpc.net to process reversed AppleScript commands. Variants written in Golang and Python show the operators experimenting with multiple runtimes to obscure activity. The source says attribution to a specific group is not confirmed, but infrastructure overlaps suggest possible links to BlueNoroff and cryptocurrency-focused social engineering.

Indicators of Compromise

Type Value First Seen Last Seen
HASH a5a530fdecf65f6a48db6c496957116… 2024-11-12 2024-11-13
HASH e96a23042a0ed4217d6a90b2ecdcee2… 2024-11-12 2024-11-13
HASH 9803e2946f19710f4f78cf5c3fea520… 2024-11-12 2024-11-13
HASH 435db426ea6410309487b2a1b3565e4… 2024-11-12 2024-11-13
HASH d62198d7d26bea9cebd71b2f04b02fe… 2024-11-12 2024-11-13
HASH 55a746c1d61cd4db4018c468749e61c… 2024-11-12 2024-11-13
HASH bfd3f0046b4c4221dfb5ae459c7ec34… 2024-11-12 2024-11-13
HASH f3d0b74410e6eb732579ba55b4e79fd… 2024-11-12 2024-11-13
HASH ab0a04e2a492fe19410ba395879a6c9… 2024-11-12 2024-11-13
DOMAIN mbupdate.linkpc.net 2024-11-12 2024-11-13

Related Reports

« Back