North Korean Malware Targets macOS Users by Evading Apple Notarization

摘要:According to Cointelegraph, North Korean hackers appear to have developed malware capable of bypassing Apple’s security checks.

Researchers at Jamf Threat Labs, specializing in Apple security, stated that the identified applications seem to be experimental. This marks the first time this technique has been observed targeting Apple‘s macOS operating system, although it does not work on the latest macOS versions. The researchers found that Microsoft’s VirusTotal online scanning service flagged these apps as harmless, while in reality, they contain malicious code. Variants of the malware are written in Go and Python and utilize Googles Flutter application framework, an open-source toolkit for building cross-platform applications.

Out of six malicious applications identified, five were signed with developer accounts and temporarily notarized by Apple. The researchers noted that the malware‘s domains and techniques bear strong similarities to those used in other North Korean hacker campaigns. There is evidence suggesting that this malware was signed and even temporarily passed Apple’s notarization process. However, it remains unclear whether the malware has been deployed in any actual attacks or if the attackers are preparing for a new method of distribution. It is likely that this is part of a broader weaponization test.

免责声明

本文观点仅代表作者个人观点,不构成本平台的投资建议,本平台不对文章信息准确性、完整性和及时性作出任何保证,亦不对因使用或信赖文章信息引发的任何损失承担责任
上一篇

加密货币大规模采用离普通人还有多远?

下一篇

QCP Capital:今日焦点为美国CPI和核心CPI的发布,可能影响美联储最终决策