#KANDYKORN

2024-08-17

"TodoSwift Disguises Malware Download Behind Bitcoin PDF" published by Kandji. #BlueNoroff, #macOS, #KANDYKORN, #DPRK, #CTI kandji.io/blog/todoswift-disgu

gtbarrygtbarry
2023-12-03

N. Korean Hackers 'Mixing' macOS Malware Tactics to Evade Detection

The North Korean threat actors behind macOS malware strains such as RustBucket and KANDYKORN have been observed "mixing and matching" different elements of the two disparate attack chains, leveraging RustBucket droppers to deliver KANDYKORN.

thehackernews.com/2023/11/n-ko

2023-11-27

"DPRK Crypto Theft | macOS RustBucket Droppers Pivot to Deliver KandyKorn Payloads" published by SentinelOne. #RustBucket, #BlueNoroff, #macOS, #KandyKorn, #CTI, #OSINT, #LAZARUS sentinelone.com/blog/dprk-cryp

🛡 H3lium@infosec.exchange/:~# :blinking_cursor:​H3liumb0y@infosec.exchange
2023-11-03

"🍬 Beware of KandyKorn 🍬 - Cryptocurrency Engineers, You're in the Crosshairs! 🎯"

A new macOS malware, 'KandyKorn', is targeting cryptocurrency engineers. Disguised as a crypto arbitrage bot, it's linked to North Korea's Lazarus group. The multi-stage attack begins on Discord and unfolds into a sophisticated backdoor operation. Stay vigilant! 🛡️💻

Tags: #KandyKorn #macOS #Malware #Cryptocurrency #Cybersecurity #LazarusGroup #InfoSec #Discord #APT

Credit: Article by Bill Toulas on BleepingComputer

Mitre - Lazarus Group

For a deep dive into the technicalities of the KandyKorn malware and its attack vectors, follow the insights of Bill Toulas, a seasoned tech writer and infosec news reporter. Stay updated and secure! 🛡️🔍

2023-11-01

To initiate their intrusion, the attackers lured blockchain engineers with a Python application, which served as the initial access point into the targeted environment.

#Cybersecurity #Apple #Blockchain #Malware #NorthKorea #macOS #Crypto #Kandykorn

cybersec84.wordpress.com/2023/

2023-10-31

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst