North Korea's Safari: Hunting for RATs

2026-04-13 Bitso

https://quetzal.bitso.com/p/north-koreas-safari-hunting-for-rats

Thumbnail for North Korea's Safari: Hunting for RATs

Bitso describes renewed Famous Chollima activity against crypto and financial organizations, including a suspicious job applicant encounter and a macOS malware kit the researchers call Mach-O Man. The infection chain starts with hijacked Telegram accounts and fake Teams, Meet, or Zoom sites that simulate a meeting failure and instruct victims to paste ClickFix terminal commands. The stager teamsSDK.bin downloads fake conferencing applications that solicit credentials, collect host reconnaissance, and launch follow-on Mach-O components for browser extension, network, and process profiling. Persistence is established through a LaunchAgent masquerading as an Antivirus Service or OneDrive component, while the macrasv2 stealer targets browser data, cookies, stored credentials, macOS Keychain entries, and other files for Telegram-based exfiltration.

Indicators of Compromise

Type Value First Seen Last Seen
HASH dfee6ea9cafc674b93a8460b9e6beea… 2026-04-13 2026-04-21
HASH cc31b3dc8aeed0af9dd24b7e739f183… 2026-04-13 2026-04-21
HASH 0f41fd82cac71e27c36eb90c0bf305d… 2026-04-13 2026-04-21
HASH eb3eae776d175f7fb2fb9986c891541… 2026-04-13 2026-04-21
HASH 4b08a9e221a20b8024cf778d113732b… 2026-04-13 2026-04-21
HASH 871d8f92b008a75607c9f1feb4922b9… 2026-04-13 2026-04-21
HASH 24af069b8899893cfc7347a4e5b46d7… 2026-04-13 2026-04-21
HASH 89616a503ffee8fc70f13c82c4a5e4f… 2026-04-13 2026-04-21
HASH 85bed283ba95d40d99e79437e6a3161… 2026-04-13 2026-04-21
HASH a9562ab6bce06e92d4e428088eacc1e… 2026-04-13 2026-04-21

Related Actors

Related Reports

« Back