BlueNoroff strikes again with new macOS malware

2023-11-07 Jamf

https://www.jamf.com/blog/bluenoroff-strikes-again-with-new-macos-malware/

Thumbnail for BlueNoroff strikes again with new macOS malware

Jamf Threat Labs attributed a new macOS later-stage malware sample, tracked as ObjCShellz, to BlueNoroff activity overlapping the RustBucket campaign. The Mach-O universal binary named ProcessRequest contacted swissborg[.]blog, a domain resembling cryptocurrency-brand infrastructure, and Jamf observed the domain resolving to 104.168.214[.]151 before the server went offline. The Objective-C malware periodically sent host and macOS version data to hxxp://swissborg.blog/zxcv/bnm, then used server responses as shell commands executed through system(). Jamf assesses the tool as a simple remote shell likely deployed after social-engineering access against financially motivated targets such as cryptocurrency exchanges, venture-capital firms, and banks.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 104.168.214.151 2023-11-07 2025-10-28
HASH 79337ccda23c67f8cfd9f43a6d3cf05… 2023-11-07 2023-11-27
URL http://swissborg.blog/zxcv/bnm 2023-11-07 2023-11-27
DOMAIN swissborg.blog 2023-11-07 2023-11-27
DOMAIN swissborg.com 2023-11-07 2023-11-13

Related Actors

Related Reports

« Back