Close Menu
    What's Hot

    What to Expect Next for Bitcoin? Which Direction is the Path Towards?

    Monday, 7 April 2025, 19:08

    BlackRock CEO Fink Warns of Further Market Drop, Recession, and Inflationary Pressures

    Monday, 7 April 2025, 16:50

    Trump Threatens 50% Additional Tariffs on China

    Monday, 7 April 2025, 16:08
    Facebook X (Twitter) Instagram
    CryptoMars
    CryptoMars
    • Home
    • News
    • Bitcoin
    • Ethereum
    • Solana
    • Cardano
    • XRP
    X (Twitter) Telegram
    CryptoMars
    Home » North Korean Hackers Target Crypto Firms with New macOS Malware
    News

    North Korean Hackers Target Crypto Firms with New macOS Malware

    Max BauerBy Max BauerSaturday, 9 November 2024, 18:09No Comments2 Mins Read

    Cybersecurity researchers have uncovered a sophisticated new malware campaign targeting cryptocurrency businesses, attributed to the North Korean hacking group BlueNoroff. The malware, dubbed “Hidden Risk” by researchers at SentinelLabs, specifically targets macOS systems and employs a multi-stage infection process involving decoy PDF documents.

    According to a recent report from SentinelLabs, the attack begins with phishing emails disseminating fabricated news stories about cryptocurrency trends. These emails contain malicious attachments disguised as legitimate PDF files. When a user downloads and opens the PDF, a separate malware file is surreptitiously downloaded onto their desktop in the background. This file then grants the attackers remote access to the victim’s computer, enabling them to steal private keys and potentially other sensitive information.

    The report highlights the advanced nature of the malware, noting a novel persistence mechanism that abuses the Zsh configuration file, zshenv. This allows the malware to remain active even after the computer is restarted, giving attackers continued access to the compromised system.

    READ  Crypto Trader Cobie Burns $17 Million Worth of Gifted Memecoin

    SentinelLabs assesses with “high confidence” that the same actor behind “Hidden Risk” is responsible for previous attacks attributed to BlueNoroff, including the RustDoor/ThiefBucket and RustBucket campaigns. This suggests a continuing evolution in the group’s tactics and techniques, specifically targeting the lucrative cryptocurrency industry.

    The discovery of “Hidden Risk” underscores the increasing sophistication of North Korean cyber operations and the ongoing threat they pose to cryptocurrency businesses and individuals. MacOS users, often perceived as less vulnerable to malware than Windows users, are particularly at risk in this campaign. Users are urged to exercise extreme caution when opening email attachments, especially those related to cryptocurrency, and to ensure their systems are running up-to-date security software. Further investigation into the “Hidden Risk” campaign is ongoing, and security researchers are working to identify and mitigate the threat.

    Related

    Max Bauer
    • Website

    Add A Comment

    Comments are closed.

    Advertisement
    Our Most Popular Articles
    • Telegram Announces Removal of "People Nearby" Feature and New Updates
      Telegram Announces Removal of "People Nearby" Feature and New Updates
    • Telegram Founder: “IP Addresses And Phone Numbers Of Users Who Violate The Rules May Be Disclosed To Relevant Agencies Upon Legal Request”
      Telegram Founder: “IP Addresses And Phone Numbers Of Users Who Violate The Rules May Be Disclosed To Relevant Agencies Upon Legal Request”
    • Home
    • Disclaimer
    • Privacy Policy
    • Contact Us
    © 2025 CryptoMars

    Disclaimer: The information on this site is for informational purposes only and should not be considered financial or investment advice. Investing in cryptocurrencies involves risk, including loss of principal. Always conduct your own research and consult with a qualified financial advisor before making any investment decisions. We are not liable for any losses or damages incurred as a result of using the information provided on this site.

    For inquiries related to news tips, advertising, partnerships, or media requests, please contact info@cryptomars.net

    Type above and press Enter to search. Press Esc to cancel.