BlueNoroff strikes again with new macOS malware
2023-11-07 • Jamf •
https://www.jamf.com/blog/bluenoroff-strikes-again-with-new-macos-malware/
Jamf Threat Labs attributed a new macOS later-stage malware sample, tracked as ObjCShellz, to BlueNoroff activity overlapping the RustBucket campaign. The Mach-O universal binary named ProcessRequest contacted swissborg[.]blog, a domain resembling cryptocurrency-brand infrastructure, and Jamf observed the domain resolving to 104.168.214[.]151 before the server went offline. The Objective-C malware periodically sent host and macOS version data to hxxp://swissborg.blog/zxcv/bnm, then used server responses as shell commands executed through system(). Jamf assesses the tool as a simple remote shell likely deployed after social-engineering access against financially motivated targets such as cryptocurrency exchanges, venture-capital firms, and banks.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 104.168.214.151 | 2023-11-07 | 2025-10-28 |
| HASH | 79337ccda23c67f8cfd9f43a6d3cf05… | 2023-11-07 | 2023-11-27 |
| URL | http://swissborg.blog/zxcv/bnm | 2023-11-07 | 2023-11-27 |
| DOMAIN | swissborg.blog | 2023-11-07 | 2023-11-27 |
| DOMAIN | swissborg.com | 2023-11-07 | 2023-11-13 |