North Korean Malware Targets macOS Users by Evading Apple Notarization

摘要:According to Cointelegraph, North Korean hackers appear to have developed malware capable of bypassing Apple’s security checks.

Researchers at Jamf Threat Labs, specializing in Apple security, stated that the identified applications seem to be experimental. This marks the first time this technique has been observed targeting Apple‘s macOS operating system, although it does not work on the latest macOS versions. The researchers found that Microsoft’s VirusTotal online scanning service flagged these apps as harmless, while in reality, they contain malicious code. Variants of the malware are written in Go and Python and utilize Googles Flutter application framework, an open-source toolkit for building cross-platform applications.

Out of six malicious applications identified, five were signed with developer accounts and temporarily notarized by Apple. The researchers noted that the malware‘s domains and techniques bear strong similarities to those used in other North Korean hacker campaigns. There is evidence suggesting that this malware was signed and even temporarily passed Apple’s notarization process. However, it remains unclear whether the malware has been deployed in any actual attacks or if the attackers are preparing for a new method of distribution. It is likely that this is part of a broader weaponization test.

免責聲明

本文觀點僅代表作者個人觀點,不構成本平台的投資建議,本平台不對文章信息準確性、完整性和及時性作出任何保證,亦不對因使用或信賴文章信息引發的任何損失承擔責任
上一篇

一文讀懂幣安Launchpad新項目Arkham,intel to earn是什麼?

下一篇

Merck與Hashgraph Group推出基於Hedera的產品護照以符合歐盟合規要求