Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Stellar retraces 37% after DTCC rally – Can XLM defend $0.183?

June 11, 2026

Genuity Subsidiary Millmerran Operating Company and ISN® Celebrate 10-Year Partnership Advancing Contractor and Supplier Compliance

June 11, 2026

Circle Introduces cirBTC on Ethereum

June 11, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»North Korean Hackers Target macOS Crypto Engineers With Kandykorn
North Korean Hackers Target macOS Crypto Engineers With Kandykorn
Security and Privacy

North Korean Hackers Target macOS Crypto Engineers With Kandykorn

November 1, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

North Korean hackers suspected to be associated with the Lazarus Group have been observed targeting blockchain engineers involved in cryptocurrency exchange platforms with a new macOS malware named Kandykorn. 

This intrusion, tracked as REF7001 by Elastic Security Labs, utilized a combination of custom and open source capabilities to gain initial access and post-exploitation on macOS systems.

Writing in an advisory published today, the security experts said the intrusion began when attackers impersonated members of the blockchain engineering community on a public Discord server, convincing victims to download and decompress a ZIP archive containing malicious code. The victim believed they were installing an arbitrage bot to profit from cryptocurrency rate differences.

The execution flow of REF7001 involved five stages:

  1. Initial Compromise: A Python application named Watcher.py was camouflaged as an arbitrage bot and was distributed in a .zip file titled “Cross-Platform Bridges.zip.”

  2. Dropper: TestSpeed.py and FinderTools were used as intermediate dropper scripts to download and execute Sugarloader.

  3. Payload: Sugarloader, an obfuscated binary, was used for initial access and as a loader for the final stage, Kandykorn.

  4. Loader: Hloader, a payload masquerading as the legitimate Discord application, was used as a persistence mechanism for loading Sugarloader.

  5. Payload: Kandykorn, the final stage of the intrusion, provided a full-featured set of capabilities for data access and exfiltration.

The Kandykorn malware communicates with a command-and-control (C2) server using encrypted RC4 and utilizes a unique handshake mechanism, waiting for commands instead of polling for them. The Elastic report details various commands that Kandykorn can execute, including file upload and download, process manipulation and execution of arbitrary system commands.

See also  New PyPI Malware “Pytoileur” Steals Crypto and Evades Detection

Read more on similar malware: Alloy Taurus Hackers Update PingPull Malware to Target Linux Systems

The Elastic team highlighted the use of reflective binary loading, a memory-resident form of execution that can bypass traditional detection methods. This type of fileless execution has been previously witnessed in attacks carried out by the Lazarus Group, with a focus on stealing cryptocurrency to circumvent international sanctions.

The technical write-up provides extensive technical details, including EQL queries for hunting and detection, as well as insights into the malware’s infrastructure and the Diamond Model used to describe the intrusion’s relationships.

Source link

Crypto Engineers Hackers Kandykorn Korean macOS North Target
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Crypto Oversight in the Spotlight After Warren Questions Federal Regulation

June 10, 2026

UK mutual funds may soon be allowed to hold crypto ETNs, but only with a 10% leash

June 10, 2026

The Flattened Curve: Why Wall Street Institutional Pools Have Reordered the Crypto Halving Cycle

June 10, 2026

The Taxation of Crypto Assets Will Be Discussed in the U.S

June 10, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Verida and inDAO Team Up to Help Uzbekistan Adopt Web3 Tech

December 17, 2023

Is This a Market Dip in a Greater Down Trend, or a Blip in a Broader Bull Run?

June 12, 2024

Franklin Templeton Strategist Sees Every National Treasury Holding Bitcoin, Says BTC Will Be Base Unit of Trade

December 17, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Stellar retraces 37% after DTCC rally – Can XLM defend $0.183?

June 11, 2026

Genuity Subsidiary Millmerran Operating Company and ISN® Celebrate 10-Year Partnership Advancing Contractor and Supplier Compliance

June 11, 2026

Circle Introduces cirBTC on Ethereum

June 11, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$62,342.001.35%
  • ethereumEthereum(ETH)$1,644.530.86%
  • tetherTether(USDT)$1.00-0.04%
  • binancecoinBNB(BNB)$593.330.92%
  • usd-coinUSDC(USDC)$1.000.01%
  • rippleXRP(XRP)$1.11-0.68%
  • solanaSolana(SOL)$64.820.45%
  • tronTRON(TRX)$0.321144-0.11%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02-0.79%
  • dogecoinDogecoin(DOGE)$0.0843170.42%