Sugarcoating KANDYKORN: a sweet dive into a sophisticated MacOS backdoor
2024-10-03 • Elastic •
Elastic describes KANDYKORN as a macOS backdoor found during an intrusion targeting engineers at a major cryptocurrency exchange platform. The malware uses a feature-rich, multi-stage loader and a custom network protocol to support post-compromise activity, including lateral movement and data exfiltration. The abstract says the loader is heavily obfuscated, reflectively loads the backdoor in memory, and uses execution flow hijacking for persistence, which is unusual in macOS environments. The delivery tradecraft includes Discord-based social lures aimed at highly targeted victims.
Related Actors
Related Reports
Shares tags: KANDYKORN, REF7001 • Same author: Elastic • Published within a week
Shares tags: macOS, KANDYKORN, REF7001 • Same author: Elastic
Shares tag: macOS • Published within a month
Shares tag: macOS • Published within a week
2024-09-09 •
30% Match
#SelectivePisces
#SmoothOperator
#RustBucket
#CollectionRAT
#KANDYKORN
#ObjCShellz
#Comebacker
#SlowPisces
#JumpyPisces
#AlluringPisces
#Fullhouse
#GleamingPisces
#OdicLoader
#POOLRAT
#PondRAT
#SparklingPisces
Shares tag: KANDYKORN • Published within a month
Shares tags: macOS, KANDYKORN