# North Korean Hackers Target macOS Users

**<mark>November 7, 2024</mark>**

---

According to fresh research from SentinelOne, the notorious **<mark>BlueNoroff</mark>** hacking team was caught **<mark>sending phishing lures with fake news headlines or stories</mark>** about crypto-related topics to targets at decentralized finance (DeFi) and cryptocurrency businesses.

Inside the emails, the North Korean government-backed **<mark>hackers embedded a malicious macOS application disguised as a link to a PDF document relating to a cryptocurrency topic such as “Hidden Risk Behind New Surge of Bitcoin Price”, “Altcoin Season 2.0-The Hidden Gems to Watch” and “New Era for Stablecoins and DeFi, CeFi”.</mark>**

SentinelOne said the campaign, called ‘Hidden Risk’, also **<mark>abuses the ‘zshenv’ configuration file to maintain persistence without triggering macOS Ventura’s </mark>** background item modification notifications.

**<mark>The macOS notifications are designed to alert users to changes in common persistence methods like LaunchAgents and LaunchDaemons.</mark>**

According to SentinelOne documentation, **<mark>the first-stage malware is a macOS application written in Swift, named identically to the embedded PDF document.</mark>** The application is signed and notarized using a legitimate Apple Developer ID (since revoked) and, upon execution,downloads a decoy PDF from a Google Drive link and opens it using the default macOS PDF viewer to avoid arousing suspicion.

In tandem, SentinelOne researchers observed **<mark> the malware downloading and executing a malicious x86-64 binary from a hard-coded URL</mark>**. The application bypasses macOS security features by specifying exceptions in its Info.plist file to **<mark>allow insecure HTTP connections, the companies said.</mark>**

The company also documented the use of **<mark>a second-stage backdoor that collects system information, generates a unique identifier, and establishes communication with a command-and-control (C2) server.</mark>**

SentinelOne said **<mark>the backdoor is programmed to send the OS version, hardware model, and process list to the C2 server and awaits further instructions.</mark>**

**<mark>BlueNoroff is publicly documented as a sub-group within North Korea’s Lazarus APT operation</mark>**.The group specializes in financial cybercrime, particularly targeting banks and cryptocurrency exchanges to fund the North Korean regime.
