North Korean Threat Actors Deploy Flutter-Based Malware to Target macOS Users – Active IOCs
2024-11-13 • Rewterz •
North Korean threat actors are described as testing or deploying macOS malware embedded in Flutter applications, including a Minesweeper-themed lure named "New Updates in Crypto Exchange (2024-08-28)." The malware uses Dart payloads, compromised Apple developer IDs, and a C2 at mbupdate.linkpc.net to process reversed AppleScript commands. Variants written in Golang and Python show the operators experimenting with multiple runtimes to obscure activity. The source says attribution to a specific group is not confirmed, but infrastructure overlaps suggest possible links to BlueNoroff and cryptocurrency-focused social engineering.
Indicators of Compromise
Related Reports
Shares tags: macOS, Flutter • Shares 10 IOCs • Published within a week
Shares tag: macOS • Published within a week
2024-11-07 •
40% Match
BlueNoroff Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel Persistence
Sentinel One
Shares tag: macOS • Published within a week
Shares tag: macOS • Published within a month
2025-02-04 •
30% Match
#macOS
#BeaverTail
#InvisibleFerret
#Lazarus
#OtterCookie
#FlexibleFerret
#FriendlyFerret
Shares tag: macOS
Shares tag: macOS