APT Actors Embed Malware within macOS Flutter Applications

2024-11-12 Jamf

https://www.jamf.com/blog/jamf-threat-labs-apt-actors-embed-malware-within-macos-flutter-applications/

Thumbnail for APT Actors Embed Malware within macOS Flutter Applications

Jamf Threat Labs found macOS malware samples it assesses as tied to DPRK activity, including Go, Py2App Python and Flutter variants that initially appeared clean on VirusTotal. The Flutter sample was a signed minesweeper style app, "New Updates in Crypto Exchange (2024-08-28).app", that contacted mbupdate[.]linkpc[.]net, a domain Jamf says has appeared in DPRK malware, to retrieve a second stage. Reversing showed Dart code embedded in the Flutter App dylib and strings indicating osascript support; in testing, the app executed reversed AppleScript returned by the server. Jamf also noted similar Golang and Python variants, temporary Apple notarization for some samples, and infrastructure and techniques overlapping prior DPRK macOS malware, while saying it was unclear whether the samples had been used against victims.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7cb8a9db65009f780d4384d5eaba7a7… 2024-11-12 2024-11-13
HASH dd38d7097a3359dc0d1c999225286a2… 2024-11-12 2024-11-13
HASH 0b9b61d0fffd52e6c37df37dfdffefc… 2024-11-12 2024-11-13
HASH 90e0e88e5b180eb1663c2b2cfe9f307… 2024-11-12 2024-11-13
HASH 9598e286142af837ee252de720aa550… 2024-11-12 2024-11-13
HASH a12ad8d16da974e2c1e9cfe6011082b… 2024-11-12 2024-11-13
HASH eadfafb35db1611350903c7a7668973… 2024-11-12 2024-11-13
HASH 6fa932f4eb5171affb7f82f88218cca… 2024-11-12 2024-11-13
HASH ee22e7768e0f4673ab954b2dd542256… 2024-11-12 2024-11-13
DOMAIN mbupdate.linkpc.net 2024-11-12 2024-11-13
HASH bc6b446bad7d76909d84e7948c36999… 2024-11-12 2024-11-12
HASH 5bf18435eb0dbb31e4056549f6ec880… 2024-11-12 2024-11-12
HASH 4476788a3178d53297caffca8ea21ab… 2024-11-12 2024-11-12
HASH 710f84c42ba79de7eebb2021383105a… 2024-11-12 2024-11-12
HASH 6664dfdbce1e6311ea02aa2827a8669… 2024-11-12 2024-11-12
HASH 2460c6ac4d55c34e3cc11c53f2e8c13… 2024-11-12 2024-11-12
HASH a2cd8cf70629b5bb0ea62278be627e2… 2024-11-12 2024-11-12
HASH 3f51182029a2d4ed9c7cc886eb76668… 2024-11-12 2024-11-12
HASH 6f280413a40d41b8dc828250bbb8940… 2024-11-12 2024-11-12
URL https://mbupdate.linkpc.net/upd… 2024-11-12 2024-11-12
IPv4 172.86.102.98 2024-11-12 2024-11-12

Related Reports

« Back