#SpectralBlur

Malware/Tool

2024-01-03 • 100DaysofYARA - SpectralBlur

SpectralBlur is an unsigned x86-64 Mach-O backdoor for macOS linked to TA444, also known as Sapphire Sleet, BLUENOROFF, and STARDUST CHOLLIMA. Its command-driven capabilities include uploading and downloading files, launching a shell, changing its configuration, deleting files, testing connectivity, and hibernating or sleeping. The malware was delivered from infrastructure associated with the Interception activity cluster. Analysts identified functional and implementation similarities to KandyKorn while assessing the two as distinct families built for comparable operational requirements.

Tagged Reports

« Back