www.rivitmedia.comwww.rivitmedia.comwww.rivitmedia.com
  • Home
  • Tech News
    Tech NewsShow More
    Microsoft’s May 2025 Patch Tuesday: Five Actively Exploited Zero-Day Vulnerabilities Addressed
    7 Min Read
    Malicious Go Modules Unleash Disk-Wiping Chaos in Linux Supply Chain Attack
    4 Min Read
    Agentic AI: Transforming Cybersecurity in 2025
    3 Min Read
    Cybersecurity CEO Accused of Planting Malware in Hospital Systems: A Breach of Trust That Shocks the Industry
    6 Min Read
    Cloud Convenience, Criminal Opportunity: How Google Sites Became a Launchpad for Elite Phishing
    6 Min Read
  • Cyber Threats
    • Malware
    • Ransomware
    • Trojans
    • Adware
    • Browser Hijackers
    • Mac Malware
    • Android Threats
    • iPhone Threats
    • Potentially Unwanted Programs (PUPs)
    • Online Scams
    • Microsoft CVE Errors
  • How-To-Guides
  • Product Reviews
    • Hardware
    • Software
  • IT/Cybersecurity Best Practices
  • FREE SCAN
  • Cybersecurity for Business
  • en English▼
    af Afrikaanssq Shqipam አማርኛar العربيةhy Հայերենaz Azərbaycan dilieu Euskarabe Беларуская моваbn বাংলাbs Bosanskibg Българскиca Catalàceb Cebuanony Chichewazh-CN 简体中文zh-TW 繁體中文co Corsuhr Hrvatskics Čeština‎da Dansknl Nederlandsen Englisheo Esperantoet Eestitl Filipinofi Suomifr Françaisfy Fryskgl Galegoka ქართულიde Deutschel Ελληνικάgu ગુજરાતીht Kreyol ayisyenha Harshen Hausahaw Ōlelo Hawaiʻiiw עִבְרִיתhi हिन्दीhmn Hmonghu Magyaris Íslenskaig Igboid Bahasa Indonesiaga Gaeilgeit Italianoja 日本語jw Basa Jawakn ಕನ್ನಡkk Қазақ тіліkm ភាសាខ្មែរko 한국어ku كوردی‎ky Кыргызчаlo ພາສາລາວla Latinlv Latviešu valodalt Lietuvių kalbalb Lëtzebuergeschmk Македонски јазикmg Malagasyms Bahasa Melayuml മലയാളംmt Maltesemi Te Reo Māorimr मराठीmn Монголmy ဗမာစာne नेपालीno Norsk bokmålps پښتوfa فارسیpl Polskipt Portuguêspa ਪੰਜਾਬੀro Românăru Русскийsm Samoangd Gàidhligsr Српски језикst Sesothosn Shonasd سنڌيsi සිංහලsk Slovenčinasl Slovenščinaso Afsoomaalies Españolsu Basa Sundasw Kiswahilisv Svenskatg Тоҷикӣta தமிழ்te తెలుగుth ไทยtr Türkçeuk Українськаur اردوuz O‘zbekchavi Tiếng Việtcy Cymraegxh isiXhosayi יידישyo Yorùbázu Zulu
Search
  • ABOUT US
  • TERMS AND SERVICES
  • SITEMAP
  • CONTACT US
© 2023 rivitMedia.com. All Rights Reserved.
Reading: ObjCShellz: Unveiling BlueNoroff’s Latest macOS Malware Linked to North Korea
Share
en English▼
af Afrikaanssq Shqipam አማርኛar العربيةhy Հայերենaz Azərbaycan dilieu Euskarabe Беларуская моваbn বাংলাbs Bosanskibg Българскиca Catalàceb Cebuanony Chichewazh-CN 简体中文zh-TW 繁體中文co Corsuhr Hrvatskics Čeština‎da Dansknl Nederlandsen Englisheo Esperantoet Eestitl Filipinofi Suomifr Françaisfy Fryskgl Galegoka ქართულიde Deutschel Ελληνικάgu ગુજરાતીht Kreyol ayisyenha Harshen Hausahaw Ōlelo Hawaiʻiiw עִבְרִיתhi हिन्दीhmn Hmonghu Magyaris Íslenskaig Igboid Bahasa Indonesiaga Gaeilgeit Italianoja 日本語jw Basa Jawakn ಕನ್ನಡkk Қазақ тіліkm ភាសាខ្មែរko 한국어ku كوردی‎ky Кыргызчаlo ພາສາລາວla Latinlv Latviešu valodalt Lietuvių kalbalb Lëtzebuergeschmk Македонски јазикmg Malagasyms Bahasa Melayuml മലയാളംmt Maltesemi Te Reo Māorimr मराठीmn Монголmy ဗမာစာne नेपालीno Norsk bokmålps پښتوfa فارسیpl Polskipt Portuguêspa ਪੰਜਾਬੀro Românăru Русскийsm Samoangd Gàidhligsr Српски језикst Sesothosn Shonasd سنڌيsi සිංහලsk Slovenčinasl Slovenščinaso Afsoomaalies Españolsu Basa Sundasw Kiswahilisv Svenskatg Тоҷикӣta தமிழ்te తెలుగుth ไทยtr Türkçeuk Українськаur اردوuz O‘zbekchavi Tiếng Việtcy Cymraegxh isiXhosayi יידישyo Yorùbázu Zulu
Notification Show More
Font ResizerAa
www.rivitmedia.comwww.rivitmedia.com
en English▼
af Afrikaanssq Shqipam አማርኛar العربيةhy Հայերենaz Azərbaycan dilieu Euskarabe Беларуская моваbn বাংলাbs Bosanskibg Българскиca Catalàceb Cebuanony Chichewazh-CN 简体中文zh-TW 繁體中文co Corsuhr Hrvatskics Čeština‎da Dansknl Nederlandsen Englisheo Esperantoet Eestitl Filipinofi Suomifr Françaisfy Fryskgl Galegoka ქართულიde Deutschel Ελληνικάgu ગુજરાતીht Kreyol ayisyenha Harshen Hausahaw Ōlelo Hawaiʻiiw עִבְרִיתhi हिन्दीhmn Hmonghu Magyaris Íslenskaig Igboid Bahasa Indonesiaga Gaeilgeit Italianoja 日本語jw Basa Jawakn ಕನ್ನಡkk Қазақ тіліkm ភាសាខ្មែរko 한국어ku كوردی‎ky Кыргызчаlo ພາສາລາວla Latinlv Latviešu valodalt Lietuvių kalbalb Lëtzebuergeschmk Македонски јазикmg Malagasyms Bahasa Melayuml മലയാളംmt Maltesemi Te Reo Māorimr मराठीmn Монголmy ဗမာစာne नेपालीno Norsk bokmålps پښتوfa فارسیpl Polskipt Portuguêspa ਪੰਜਾਬੀro Românăru Русскийsm Samoangd Gàidhligsr Српски језикst Sesothosn Shonasd سنڌيsi සිංහලsk Slovenčinasl Slovenščinaso Afsoomaalies Españolsu Basa Sundasw Kiswahilisv Svenskatg Тоҷикӣta தமிழ்te తెలుగుth ไทยtr Türkçeuk Українськаur اردوuz O‘zbekchavi Tiếng Việtcy Cymraegxh isiXhosayi יידישyo Yorùbázu Zulu
Font ResizerAa
  • Online Scams
  • Tech News
  • Cyber Threats
  • Mac Malware
  • Cybersecurity for Business
  • FREE SCAN
Search
  • Home
  • Tech News
  • Cyber Threats
    • Malware
    • Ransomware
    • Trojans
    • Adware
    • Browser Hijackers
    • Mac Malware
    • Android Threats
    • iPhone Threats
    • Potentially Unwanted Programs (PUPs)
    • Online Scams
  • How-To-Guides
  • Product Reviews
    • Hardware
    • Software
  • IT/Cybersecurity Best Practices
    • Cybersecurity for Business
  • FREE SCAN
  • Sitemap
Follow US
  • ABOUT US
  • TERMS AND SERVICES
  • SITEMAP
  • CONTACT US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
www.rivitmedia.com > Blog > Cyber Threats > Mac Malware > ObjCShellz: Unveiling BlueNoroff’s Latest macOS Malware Linked to North Korea
How-To-GuidesIT/Cybersecurity Best PracticesMac MalwareTech News

ObjCShellz: Unveiling BlueNoroff’s Latest macOS Malware Linked to North Korea

riviTMedia Research
Last updated: November 8, 2023 5:06 pm
riviTMedia Research
Share
ObjCShellz: Unveiling BlueNoroff's Latest macOS Malware Linked to North Korea
SHARE

Cybersecurity researchers have recently uncovered a new macOS malware strain known as ObjCShellz, attributed to the North Korea-linked nation-state group, BlueNoroff. This group has a history of engaging in five ransomware-as-a-service (RaaS) programs over the past four years, highlighting the severity of the cybersecurity threat. In this article, we will delve into the details of ObjCShellz, its association with the RustBucket malware campaign, and the broader activities of the BlueNoroff group.

Contents
ObjCShellz and RustBucket Malware CampaignBlueNoroff: A Subgroup of Lazarus GroupObjCShellz: A Simple Yet Potent Remote ShellPossible Targets and Modus OperandiCollaborative Landscape of North Korea-Sponsored GroupsInternational Response to North Korea’s Cyber ActivitiesRemoval GuideSafeguarding Your SystemConclusion

ObjCShellz and RustBucket Malware Campaign

ObjCShellz is identified as a component of the RustBucket malware campaign, which gained attention in the cybersecurity community earlier this year. Researchers from Jamf Threat Labs have disclosed information about ObjCShellz, shedding light on its role in this sophisticated malware campaign orchestrated by BlueNoroff.

BlueNoroff: A Subgroup of Lazarus Group

Operating under various aliases, including APT38, Nickel Gladstone, Sapphire Sleet, Stardust Chollima, and TA444, BlueNoroff is a subgroup of the notorious Lazarus Group. BlueNoroff is known for its involvement in financial crimes, with a specific focus on targeting banks and the cryptocurrency sector. Their primary objective is to circumvent sanctions and generate illicit profits for the North Korean regime.

ObjCShellz: A Simple Yet Potent Remote Shell

ObjCShellz is coded in Objective-C and functions as a remote shell capable of executing commands sent from the attacker’s server. Despite its apparent simplicity, this malware serves as a late-stage component within a multi-stage attack, often delivered through social engineering tactics.

Possible Targets and Modus Operandi

While the specific targets of ObjCShellz remain undisclosed, the malware’s functionalities suggest a probable focus on companies within the cryptocurrency industry or closely associated sectors. BlueNoroff’s intricate campaigns often lure victims with promises of investment advice or job opportunities before initiating the infection chain with a decoy document.

Collaborative Landscape of North Korea-Sponsored Groups

The revelation of ObjCShellz follows recent findings of the Lazarus Group’s use of another macOS malware, KANDYKORN, which was specifically targeting blockchain engineers. This interconnected nature of North Korea-sponsored groups, sharing tools and tactics, indicates a collaborative and evolving approach among them.

International Response to North Korea’s Cyber Activities

In response to the escalating cyber activities linked to North Korea, the United States, South Korea, and Japan have established a trilateral high-level cyber consultative group. The primary objective of this cooperative effort is to counter cyber activities that serve as a significant funding source for North Korea’s weapons development.

Removal Guide

To remove ObjCShellz or similar malware from your macOS, follow these steps:

  1. Disconnect from the Internet: Disable your internet connection to prevent further communication between the malware and the attacker’s server.
  2. Back Up Your Data: Before taking any actions, ensure you have a backup of your important data to avoid data loss.
  3. Identify Malicious Processes: Use macOS utilities like Activity Monitor or Terminal to identify and terminate any suspicious processes related to the malware.
  4. Delete Malicious Files: Locate and delete the malicious files associated with ObjCShellz. These files may be in hidden folders or within system directories, so use caution.
  5. Reset Browsers: If your web browser settings were compromised, reset them to their default settings to remove any unwanted extensions or modifications.
  6. Install Antivirus Software: Install reputable antivirus software for macOS and run a full system scan to detect and remove any remaining malware or threats.
  7. Change Passwords: Change your passwords, especially for sensitive accounts, to prevent unauthorized access.

Safeguarding Your System

To protect your system from similar threats in the future:

  1. Keep Software Updated: Regularly update your macOS, applications, and security software to patch known vulnerabilities.
  2. Practice Safe Downloading: Only download software from trusted sources and avoid third-party or unverified websites.
  3. Enable Firewall: Activate the built-in firewall on your macOS for an added layer of protection.
  4. Exercise Caution with Email: Be wary of email attachments and links, especially from unknown or suspicious sources.
  5. Educate Yourself: Stay informed about the latest cybersecurity threats and best practices for online safety.

Conclusion

ObjCShellz, as part of the RustBucket malware campaign orchestrated by BlueNoroff, is the latest addition to North Korea’s evolving cyber threat landscape. The interconnected and collaborative nature of North Korea-sponsored groups underscores the need for international cooperation to counter the growing cyber threats emanating from the region. By following the removal guide and implementing preventive measures, you can enhance your cybersecurity and protect your system from persistent and sophisticated threat actors. Stay vigilant, stay secure.

You Might Also Like

QuestDevice: The Adware Onslaught
Mog Coin Scam & Associated Malware
DiprotodonOptatum – Unveiling a Malicious Browser Extension
Kematian Stealer: A Comprehensive Guide to Detection and Removal
Odejdi.info Adware: An Annoying Menace to Your Online Privacy & Security
TAGGED:Best PracticesLazarus RansomwareMalwareRaaSTech News

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.

Your Details

Let us know how to get back to you.

Example: user@website.com
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Copy Link Print
Share
Previous Article Search4Word Browser Hijacker: Removal Guide and Prevention Tips
Next Article Revealing Farnetwork: Insights from a Unique “Job Interview” Process
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Scan Your System for Free

✅ Free Scan Available 

✅ 13M Scans/Month

✅ Instant Detection

Download SpyHunter 5
Download SpyHunter for Mac

//

Check in Daily for the best technology and Cybersecurity based content on the internet.

Quick Link

  • ABOUT US
  • TERMS AND SERVICES
  • SITEMAP
  • CONTACT US

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

Your Details

Let us know how to get back to you.

Example: user@website.com
www.rivitmedia.comwww.rivitmedia.com
© 2023 • rivitmedia.com All Rights Reserved.
  • ABOUT US
  • TERMS AND SERVICES
  • SITEMAP
  • CONTACT US