Inside the BlueNoroff Web3 macOS Intrusion Analysis
2025-06-18 • Huntress •
https://www.huntress.com/blog/inside-bluenoroff-web3-intrusion-analysis
Huntress attributes a macOS intrusion against a cryptocurrency foundation employee to TA444/BlueNoroff, a DPRK subgroup also tracked as Sapphire Sleet, COPERNICIUM, STARDUST CHOLLIMA, or CageyChameleon. The attacker used Telegram contact, Calendly and Google Meet pretexts, a fake Zoom support domain, and deepfaked company leadership to persuade the victim to install a malicious AppleScript presented as a Zoom extension. The chain disabled shell history, checked for Rosetta 2, attempted to collect the user password, and deployed multiple macOS implants including Telegram 2 for persistence, the Go-based Root Troy V4/remoted backdoor, InjectWithDyld, a Nim command-execution payload, XScreen, and CryptoBot. The tooling supported command execution, interactive shells, payload deployment, keylogging, clipboard and screen monitoring, and collection of cryptocurrency-related files, making the intrusion directly relevant to DPRK cryptocurrency theft tracking.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | support.us05web-zoom.biz | 2025-06-18 | 2026-01-01 |
| HASH | c4db903322d17c8cbf1d1db55124854… | 2025-06-18 | 2025-10-28 |
| HASH | 3dd226d0b700f33974f409142defb62… | 2025-06-18 | 2025-10-28 |
| URL | https://metamask.awaitingfor.si… | 2025-06-18 | 2025-10-28 |
| DOMAIN | metamask.awaitingfor.site | 2025-06-18 | 2025-10-28 |
| DOMAIN | safefor.xyz | 2025-06-18 | 2025-10-28 |
| DOMAIN | readysafe.xyz | 2025-06-18 | 2025-10-28 |
| HASH | 469fd8a280e89a6edd0d704d0be4c7e… | 2025-04-23 | 2025-07-14 |
| HASH | 1ddef717bf82e61bf79b24570ab68bf… | 2025-06-18 | 2025-06-18 |
| HASH | ad21af758af28b7675c55e64bf5a9b3… | 2025-06-18 | 2025-06-18 |
| HASH | 080a52b99d997e1ac60bd096a626b4d… | 2025-06-18 | 2025-06-18 |
| HASH | 432c720a9ada40785d77cd7e5798de8… | 2025-06-18 | 2025-06-18 |
| HASH | 14e9bb6df4906691fc7754cf7906c34… | 2025-06-18 | 2025-06-18 |
| HASH | 2e30c9e3f0324011eb983eef31d82a1… | 2025-06-18 | 2025-06-18 |
| HASH | 4cd5df82e1d4f93361e71624730fbd1… | 2025-06-18 | 2025-06-18 |
| HASH | ad01beb19f5b8c7155ee5415781761d… | 2025-06-18 | 2025-06-18 |