North Korea's Safari: Hunting for RATs
2026-04-13 • Bitso •
https://quetzal.bitso.com/p/north-koreas-safari-hunting-for-rats
Bitso describes renewed Famous Chollima activity against crypto and financial organizations, including a suspicious job applicant encounter and a macOS malware kit the researchers call Mach-O Man. The infection chain starts with hijacked Telegram accounts and fake Teams, Meet, or Zoom sites that simulate a meeting failure and instruct victims to paste ClickFix terminal commands. The stager teamsSDK.bin downloads fake conferencing applications that solicit credentials, collect host reconnaissance, and launch follow-on Mach-O components for browser extension, network, and process profiling. Persistence is established through a LaunchAgent masquerading as an Antivirus Service or OneDrive component, while the macrasv2 stealer targets browser data, cookies, stored credentials, macOS Keychain entries, and other files for Telegram-based exfiltration.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | dfee6ea9cafc674b93a8460b9e6beea… | 2026-04-13 | 2026-04-21 |
| HASH | cc31b3dc8aeed0af9dd24b7e739f183… | 2026-04-13 | 2026-04-21 |
| HASH | 0f41fd82cac71e27c36eb90c0bf305d… | 2026-04-13 | 2026-04-21 |
| HASH | eb3eae776d175f7fb2fb9986c891541… | 2026-04-13 | 2026-04-21 |
| HASH | 4b08a9e221a20b8024cf778d113732b… | 2026-04-13 | 2026-04-21 |
| HASH | 871d8f92b008a75607c9f1feb4922b9… | 2026-04-13 | 2026-04-21 |
| HASH | 24af069b8899893cfc7347a4e5b46d7… | 2026-04-13 | 2026-04-21 |
| HASH | 89616a503ffee8fc70f13c82c4a5e4f… | 2026-04-13 | 2026-04-21 |
| HASH | 85bed283ba95d40d99e79437e6a3161… | 2026-04-13 | 2026-04-21 |
| HASH | a9562ab6bce06e92d4e428088eacc1e… | 2026-04-13 | 2026-04-21 |