BlueNoroff, a North Korean state-sponsored threat actor, has been targeting crypto businesses with a new piece of malware that establishes persistence and opens a back door. The malware, part of a campaign named “Hidden Risk”, is delivered through a phishing email with a fake news PDF file that redirects victims to a malicious website. The malware, called “growth”, only works on macOS devices and can download additional payloads, run Shell commands, and check in with a C2 server for new commands every minute.
Full Article
