#Armadillos
Malware/Tool
2026-02-21 • North Korea's Safari: Poaching for Armadillos
Armadillos is associated with POWerful Armadillo, a modular macOS stealer and backdoor delivered through compromised WhatsApp accounts and a fake WebEx DMG. Its scripts capture user credentials, collect Apple Notes and small documents, steal Keychain data, browser credentials and cookies, cryptocurrency wallets, Telegram files, and other application data, and upload archives to command-and-control infrastructure. A LaunchAgent provides persistence, while a JXA agent fingerprints hosts, executes Bash, AppleScript, or JXA tasks, and solves proof-of-work challenges before interacting with its server.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days