#ChaoticCapybara

Malware/Tool

2025-03-24 • Cómo domar un Chollima

ChaoticCapybara is C++ malware compiled for Apple Silicon macOS systems and distributed in North Korean fake-interview and fraudulent Zoom-update activity targeting cryptocurrency and Web3 personnel. The ARM64 Mach-O binary checks security and execution-environment properties, attempts to interact with System Integrity Protection and mandatory access controls, and installs itself under /Library/DnsService. It opens connections to Hostwinds infrastructure and launches an XScreen subprocess that communicates with a separate server, behavior assessed as screen-activity transmission. The campaign delivered it through cloned meeting sites after social engineering victims into installing a supposed audio-fix update.

Tagged Reports

« Back