#Koi

Malware/Tool

2025-02-26 • RustDoor and Koi Stealer for macOS Used by North Korea-Linked Threat Actor to Target the Cryptocurrency Sector

Koi Stealer is an information-stealing family with Windows and macOS variants; a previously undocumented macOS build was used in a campaign targeting job-seeking cryptocurrency developers. Masquerading as a Visual Studio update, it repeatedly prompted for administrator credentials, collected the username, password, hardware UUID, and installed applications, then stole browser data, FileZilla and OpenVPN files, Steam and Discord data, Telegram files, SSH configurations, Keychains, Notes, documents, and cryptocurrency wallets. Koi encrypted and exfiltrated the material to command-and-control infrastructure and used AppleScript to mute the system while copying selected files.

Tagged Reports

« Back