North Korea's Safari: Poaching for Armadillos

2026-02-21 Bitso

https://quetzal.bitso.com/p/north-koreas-safari-poaching-for

Thumbnail for North Korea's Safari: Poaching for Armadillos

Quetzal details POWerful Armadillo, a newly named DPRK macOS malware family delivered through compromised WhatsApp accounts posing as a WebEx installer. The infection chain begins with a DMG containing a Bash-based installer, then pulls obfuscated Bash, JavaScript/JXA, and AppleScript components that prompt for credentials, steal Keychain, browser, wallet, Telegram, Apple Notes, and user-directory files, and establish LaunchAgent persistence. The persistent JXA agent fingerprints hosts, polls command-and-control, executes remote Bash/AppleScript/JXA tasks, and gates C2 interactions behind a SHA-256 proof-of-work challenge. Reported infrastructure includes 62.60.226.225, hoplokiroute[.]com, a Cloudflare Pages staging domain, multiple staged ASPX-looking URLs, and SHA-256 hashes for the macOS components, making the report useful for tracking DPRK developer- and crypto-focused macOS intrusion tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f5669d80eb52f8b6fc90f5c5db98182… 2026-02-21 2026-02-21
HASH 0c47f6db79f5c4db86227b1fba4528c… 2026-02-21 2026-02-21
HASH 91c47f8ddb5a937c461bee602156954… 2026-02-21 2026-02-21
HASH e4677a8fb20517393a761c49075f0e4… 2026-02-21 2026-02-21
HASH 318792ed0fcb64059670956468d7e0e… 2026-02-21 2026-02-21
HASH ee93c0caa82ed4b362b1f13b230687c… 2026-02-21 2026-02-21
HASH 66c3d0eaf68dcc97c092ce48ed65df4… 2026-02-21 2026-02-21
HASH 7f78ce8bd2c7e2ccd71fc62bcfb29ce… 2026-02-21 2026-02-21
URL https://hoplokiroute.com/SifFSY… 2026-02-21 2026-02-21
URL https://hylb9pbsjaqkl03g75jomhr… 2026-02-21 2026-02-21
URL https://hylb9pbsjaqkl03g75jomhr… 2026-02-21 2026-02-21
URL https://hoplokiroute.com/hicMvd… 2026-02-21 2026-02-21
URL https://hylb9pbsjaqkl03g75jomhr… 2026-02-21 2026-02-21
URL https://hylb9pbsjaqkl03g75jomhr… 2026-02-21 2026-02-21
URL https://hoplokiroute.com/wuZpFO… 2026-02-21 2026-02-21
URL https://hylb9pbsjaqkl03g75jomhr… 2026-02-21 2026-02-21
URL https://hylb9pbsjaqkl03g75jomhr… 2026-02-21 2026-02-21
URL https://hylb9pbsjaqkl03g75jomhr… 2026-02-21 2026-02-21
DOMAIN hylb9pbsjaqkl03g75jomhrsitz0msi… 2026-02-21 2026-02-21
DOMAIN hoplokiroute.com 2026-02-21 2026-02-21
DOMAIN install.xyz 2026-02-21 2026-02-21
IPv4 62.60.226.225 2026-02-21 2026-02-21

Related Actors

Related Reports

« Back