Inside the BlueNoroff Web3 macOS Intrusion Analysis

2025-06-18 Huntress

https://www.huntress.com/blog/inside-bluenoroff-web3-intrusion-analysis

Thumbnail for Inside the BlueNoroff Web3 macOS Intrusion Analysis

Huntress attributes a macOS intrusion against a cryptocurrency foundation employee to TA444/BlueNoroff, a DPRK subgroup also tracked as Sapphire Sleet, COPERNICIUM, STARDUST CHOLLIMA, or CageyChameleon. The attacker used Telegram contact, Calendly and Google Meet pretexts, a fake Zoom support domain, and deepfaked company leadership to persuade the victim to install a malicious AppleScript presented as a Zoom extension. The chain disabled shell history, checked for Rosetta 2, attempted to collect the user password, and deployed multiple macOS implants including Telegram 2 for persistence, the Go-based Root Troy V4/remoted backdoor, InjectWithDyld, a Nim command-execution payload, XScreen, and CryptoBot. The tooling supported command execution, interactive shells, payload deployment, keylogging, clipboard and screen monitoring, and collection of cryptocurrency-related files, making the intrusion directly relevant to DPRK cryptocurrency theft tracking.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN support.us05web-zoom.biz 2025-06-18 2026-01-01
HASH c4db903322d17c8cbf1d1db55124854… 2025-06-18 2025-10-28
HASH 3dd226d0b700f33974f409142defb62… 2025-06-18 2025-10-28
URL https://metamask.awaitingfor.si… 2025-06-18 2025-10-28
DOMAIN metamask.awaitingfor.site 2025-06-18 2025-10-28
DOMAIN safefor.xyz 2025-06-18 2025-10-28
DOMAIN readysafe.xyz 2025-06-18 2025-10-28
HASH 469fd8a280e89a6edd0d704d0be4c7e… 2025-04-23 2025-07-14
HASH 1ddef717bf82e61bf79b24570ab68bf… 2025-06-18 2025-06-18
HASH ad21af758af28b7675c55e64bf5a9b3… 2025-06-18 2025-06-18
HASH 080a52b99d997e1ac60bd096a626b4d… 2025-06-18 2025-06-18
HASH 432c720a9ada40785d77cd7e5798de8… 2025-06-18 2025-06-18
HASH 14e9bb6df4906691fc7754cf7906c34… 2025-06-18 2025-06-18
HASH 2e30c9e3f0324011eb983eef31d82a1… 2025-06-18 2025-06-18
HASH 4cd5df82e1d4f93361e71624730fbd1… 2025-06-18 2025-06-18
HASH ad01beb19f5b8c7155ee5415781761d… 2025-06-18 2025-06-18

Related Actors

Related Reports

« Back