Node.js Backdoor Used in DPRK Malvertising Campaign
A Node.js backdoor deployed via fake macOS updates, using LaunchAgent for persistence and Ethereum smart contracts for C2 communication. It polls the…
A Node.js backdoor deployed via fake macOS updates, using LaunchAgent for persistence and Ethereum smart contracts for C2 communication. It polls the…
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake…
Group-IB has identified a new macOS infostealer, ClickLock Stealer, that uses a coercive technique to force victims to enter their login password.…
LaunchAgent is a macOS persistence mechanism used by the Node.js backdoor in the DPRK malvertising campaign to maintain access on infected systems.