Node.js Backdoor Used in DPRK Malvertising Campaign
A Node.js backdoor deployed via fake macOS updates, using LaunchAgent for persistence and Ethereum smart contracts for C2 communication. It polls the…
A Node.js backdoor deployed via fake macOS updates, using LaunchAgent for persistence and Ethereum smart contracts for C2 communication. It polls the…
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake…