North Korean hackers, likely associated with the Lazarus, are targeting blockchain engineers working on platforms crypto exchange The hackers are using a new macOS malware called Kandykorn.
This attack, which is being tracked as REF7001 by Elastic Security Labs, used a combination of custom and open source solutions to gain access and continue exploiting macOS systems.

Security researchers said the attack began when attackers posed as members of the blockchain engineering community on a public Discord. The hackers convinced victims to download and decompress a file ZIP containing malicious code. The victim believed they were installing an arbitrage bot to profit from differences in crypto prices.
See also: FSB arrested Russian hackers who were helping Ukraine
The attack included five stages:
- Initial breach: A Python application named Watcher.py appears to be an arbitrage bot and is distributed within a .zip file titled “Cross-Platform Bridges.zip“.
- Dropper: TestSpeed.py and FinderTools were used as intermediate dropper scripts to download and run Sugarloader.
- Payload: Sugarloader, an obfuscated binary, was used for initial access and as a loader for the final stage, Kandykorn.
- Loader: Hloader, a payload disguised as the legitimate Discord app, was used as a persistence mechanism to load Sugarloader.
- Payload: Kandykorn, the final stage of the attack, allowed access and data theft.
The macOS malware Kandykorn communicates with a command-and-control (C2) server using encrypted RC4 and uses a unique handshake mechanism, waiting for commands. The Elastic report details various commands that Kandykorn can execute. Some of these include sending and receiving files, manipulating processes, and executing system commands.
See also: Turla hackers: New more dangerous version of Kazuar backdoor
The researchers highlighted the use of reflective binary loading, which can bypass traditional detection methods. This type of fileless execution has been observed in attacks by Lazarus hackers, with a focus on stealing cryptocurrency to circumvent international sanctions.

Malware protection
One of the best ways to protect your device from MacOS malware is to install a reliable antivirus program. Antivirus programs can detect and remove malware before it can cause damage to your system. Choose an antivirus that offers continuous updates and protection against the latest threats.
Another important way to prevent this is to update your operating system and applications regularly. Updates often contain security that can prevent malware from entering. Make sure you have automatic updates turned on so you don't miss any important upgrades.
See also: Cyber espionage: Iranian hackers Scarred Manticore target organizations in the Middle East
Additionally, it's important to be careful about how you download and install apps on your MacOS system. Avoid downloading apps from untrusted sources and prefer the Mac App Store to ensure that the apps are official and safe. Also, read reviews and ratings from other users before installing an app.
Finally, a good practice for preventing MacOS malware is to disable the automatic execution of unwanted applications and files. Some malware can exploit this feature to invade your system. Set your system preferences to require your approval before executing unwanted files.
Source: www.infosecurity-magazine.com
