North Korean Malware Targets macOS Users by Evading Apple Notarization

概要:According to Cointelegraph, North Korean hackers appear to have developed malware capable of bypassing Apple’s security checks.

Researchers at Jamf Threat Labs, specializing in Apple security, stated that the identified applications seem to be experimental. This marks the first time this technique has been observed targeting Apple‘s macOS operating system, although it does not work on the latest macOS versions. The researchers found that Microsoft’s VirusTotal online scanning service flagged these apps as harmless, while in reality, they contain malicious code. Variants of the malware are written in Go and Python and utilize Googles Flutter application framework, an open-source toolkit for building cross-platform applications.

Out of six malicious applications identified, five were signed with developer accounts and temporarily notarized by Apple. The researchers noted that the malware‘s domains and techniques bear strong similarities to those used in other North Korean hacker campaigns. There is evidence suggesting that this malware was signed and even temporarily passed Apple’s notarization process. However, it remains unclear whether the malware has been deployed in any actual attacks or if the attackers are preparing for a new method of distribution. It is likely that this is part of a broader weaponization test.

免責事項

このコンテンツの見解は筆者個人的な見解を示すものに過ぎず、当社の投資アドバイスではありません。当サイトは、記事情報の正確性、完全性、適時性を保証するものではなく、情報の使用または関連コンテンツにより生じた、いかなる損失に対しても責任は負いません。
前へ

「11月13日」WikiBit速報まとめ

次へ

ライブ市場:ウォーシュ氏の発言および経済指標を受けて、ビットコインが60,000ドルに回復