North Korean Threat Actors Deploy Flutter-Based Malware to Target macOS Users – Active IOCs
2024-11-13 • Rewterz •
North Korean threat actors are described as testing or deploying macOS malware embedded in Flutter applications, including a Minesweeper-themed lure named "New Updates in Crypto Exchange (2024-08-28)." The malware uses Dart payloads, compromised Apple developer IDs, and a C2 at mbupdate.linkpc.net to process reversed AppleScript commands. Variants written in Golang and Python show the operators experimenting with multiple runtimes to obscure activity. The source says attribution to a specific group is not confirmed, but infrastructure overlaps suggest possible links to BlueNoroff and cryptocurrency-focused social engineering.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | a5a530fdecf65f6a48db6c496957116… | 2024-11-12 | 2024-11-13 |
| HASH | e96a23042a0ed4217d6a90b2ecdcee2… | 2024-11-12 | 2024-11-13 |
| HASH | 9803e2946f19710f4f78cf5c3fea520… | 2024-11-12 | 2024-11-13 |
| HASH | 435db426ea6410309487b2a1b3565e4… | 2024-11-12 | 2024-11-13 |
| HASH | d62198d7d26bea9cebd71b2f04b02fe… | 2024-11-12 | 2024-11-13 |
| HASH | 55a746c1d61cd4db4018c468749e61c… | 2024-11-12 | 2024-11-13 |
| HASH | bfd3f0046b4c4221dfb5ae459c7ec34… | 2024-11-12 | 2024-11-13 |
| HASH | f3d0b74410e6eb732579ba55b4e79fd… | 2024-11-12 | 2024-11-13 |
| HASH | ab0a04e2a492fe19410ba395879a6c9… | 2024-11-12 | 2024-11-13 |
| DOMAIN | mbupdate.linkpc.net | 2024-11-12 | 2024-11-13 |
Related Reports
Shares tags: macOS, Flutter • Shares 10 IOCs • Published within a week
Shares tag: macOS • Published within a week
2024-11-07 •
40% Match
BlueNoroff Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel Persistence
Sentinel One
Shares tag: macOS • Published within a week
Shares tag: macOS • Published within a month
2025-02-04 •
30% Match
#macOS
#BeaverTail
#InvisibleFerret
#Lazarus
#OtterCookie
#FlexibleFerret
#FriendlyFerret
Shares tag: macOS
Shares tag: macOS