www.rivitmedia.comwww.rivitmedia.comwww.rivitmedia.com
  • Home
  • Tech News
    Tech NewsShow More
    Agent Racoon: The Stealthy Backdoor Threat Targeting Organizations
    2 Min Read
    malware
    NSudo Exploitation: Understanding the Legitimate Tool Turned Malware
    4 Min Read
    malware
    LitterDrifter Worm: Threat Insights and Removal Guide
    3 Min Read
    SimpleNavigation Adware: Risks, Prevention, and Removal Guide
    6 Min Read
    Zimbra Email Software Vulnerability: Understanding, Mitigating, and Preventing Cyber Threats
    9 Min Read
  • Cyber Threats
    • Malware
    • Ransomware
    • Trojans
    • Adware
    • Browser Hijackers
    • Mac Malware
    • Android Threats
    • iPhone Threats
    • Potentially Unwanted Programs (PUPs)
    • Online Scams
  • How-To-Guides
  • Product Reviews
    • Hardware
    • Software
  • IT/Cybersecurity Best Practices
Search
  • ABOUT US
  • TERMS AND SERVICES
  • SITEMAP
  • CONTACT US
© 2023 rivitMedia.com. All Rights Reserved.
Reading: ObjCShellz: Unveiling BlueNoroff’s Latest macOS Malware Linked to North Korea
Share
Notification Show More
Font ResizerAa
www.rivitmedia.comwww.rivitmedia.com
Font ResizerAa
  • Online Scams
  • Tech News
  • Cyber Threats
  • Mac Malware
Search
  • Home
  • Tech News
  • Cyber Threats
    • Malware
    • Ransomware
    • Trojans
    • Adware
    • Browser Hijackers
    • Mac Malware
    • Android Threats
    • iPhone Threats
    • Potentially Unwanted Programs (PUPs)
    • Online Scams
  • How-To-Guides
  • Product Reviews
    • Hardware
    • Software
  • IT/Cybersecurity Best Practices
  • Sitemap
Follow US
  • ABOUT US
  • TERMS AND SERVICES
  • SITEMAP
  • CONTACT US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
www.rivitmedia.com > Blog > Cyber Threats > Mac Malware > ObjCShellz: Unveiling BlueNoroff’s Latest macOS Malware Linked to North Korea
How-To-GuidesIT/Cybersecurity Best PracticesMac MalwareTech News

ObjCShellz: Unveiling BlueNoroff’s Latest macOS Malware Linked to North Korea

riviTMedia Research
Last updated: 2023/11/08 at 5:06 PM
riviTMedia Research
Share
ObjCShellz: Unveiling BlueNoroff's Latest macOS Malware Linked to North Korea
SHARE

Cybersecurity researchers have recently uncovered a new macOS malware strain known as ObjCShellz, attributed to the North Korea-linked nation-state group, BlueNoroff. This group has a history of engaging in five ransomware-as-a-service (RaaS) programs over the past four years, highlighting the severity of the cybersecurity threat. In this article, we will delve into the details of ObjCShellz, its association with the RustBucket malware campaign, and the broader activities of the BlueNoroff group.

Contents
ObjCShellz and RustBucket Malware CampaignBlueNoroff: A Subgroup of Lazarus GroupObjCShellz: A Simple Yet Potent Remote ShellPossible Targets and Modus OperandiCollaborative Landscape of North Korea-Sponsored GroupsInternational Response to North Korea’s Cyber ActivitiesRemoval GuideSafeguarding Your SystemConclusion

ObjCShellz and RustBucket Malware Campaign

ObjCShellz is identified as a component of the RustBucket malware campaign, which gained attention in the cybersecurity community earlier this year. Researchers from Jamf Threat Labs have disclosed information about ObjCShellz, shedding light on its role in this sophisticated malware campaign orchestrated by BlueNoroff.

BlueNoroff: A Subgroup of Lazarus Group

Operating under various aliases, including APT38, Nickel Gladstone, Sapphire Sleet, Stardust Chollima, and TA444, BlueNoroff is a subgroup of the notorious Lazarus Group. BlueNoroff is known for its involvement in financial crimes, with a specific focus on targeting banks and the cryptocurrency sector. Their primary objective is to circumvent sanctions and generate illicit profits for the North Korean regime.

ObjCShellz: A Simple Yet Potent Remote Shell

ObjCShellz is coded in Objective-C and functions as a remote shell capable of executing commands sent from the attacker’s server. Despite its apparent simplicity, this malware serves as a late-stage component within a multi-stage attack, often delivered through social engineering tactics.

Possible Targets and Modus Operandi

While the specific targets of ObjCShellz remain undisclosed, the malware’s functionalities suggest a probable focus on companies within the cryptocurrency industry or closely associated sectors. BlueNoroff’s intricate campaigns often lure victims with promises of investment advice or job opportunities before initiating the infection chain with a decoy document.

Collaborative Landscape of North Korea-Sponsored Groups

The revelation of ObjCShellz follows recent findings of the Lazarus Group’s use of another macOS malware, KANDYKORN, which was specifically targeting blockchain engineers. This interconnected nature of North Korea-sponsored groups, sharing tools and tactics, indicates a collaborative and evolving approach among them.

International Response to North Korea’s Cyber Activities

In response to the escalating cyber activities linked to North Korea, the United States, South Korea, and Japan have established a trilateral high-level cyber consultative group. The primary objective of this cooperative effort is to counter cyber activities that serve as a significant funding source for North Korea’s weapons development.

Removal Guide

To remove ObjCShellz or similar malware from your macOS, follow these steps:

  1. Disconnect from the Internet: Disable your internet connection to prevent further communication between the malware and the attacker’s server.
  2. Back Up Your Data: Before taking any actions, ensure you have a backup of your important data to avoid data loss.
  3. Identify Malicious Processes: Use macOS utilities like Activity Monitor or Terminal to identify and terminate any suspicious processes related to the malware.
  4. Delete Malicious Files: Locate and delete the malicious files associated with ObjCShellz. These files may be in hidden folders or within system directories, so use caution.
  5. Reset Browsers: If your web browser settings were compromised, reset them to their default settings to remove any unwanted extensions or modifications.
  6. Install Antivirus Software: Install reputable antivirus software for macOS and run a full system scan to detect and remove any remaining malware or threats.
  7. Change Passwords: Change your passwords, especially for sensitive accounts, to prevent unauthorized access.

Safeguarding Your System

To protect your system from similar threats in the future:

  1. Keep Software Updated: Regularly update your macOS, applications, and security software to patch known vulnerabilities.
  2. Practice Safe Downloading: Only download software from trusted sources and avoid third-party or unverified websites.
  3. Enable Firewall: Activate the built-in firewall on your macOS for an added layer of protection.
  4. Exercise Caution with Email: Be wary of email attachments and links, especially from unknown or suspicious sources.
  5. Educate Yourself: Stay informed about the latest cybersecurity threats and best practices for online safety.

Conclusion

ObjCShellz, as part of the RustBucket malware campaign orchestrated by BlueNoroff, is the latest addition to North Korea’s evolving cyber threat landscape. The interconnected and collaborative nature of North Korea-sponsored groups underscores the need for international cooperation to counter the growing cyber threats emanating from the region. By following the removal guide and implementing preventive measures, you can enhance your cybersecurity and protect your system from persistent and sophisticated threat actors. Stay vigilant, stay secure.

You Might Also Like

Agent Racoon: The Stealthy Backdoor Threat Targeting Organizations

Removing MegaUnit.gqa: A Browser Hijacker Threat

ElementaryType.gqa: Preventive Measures and Removal Guide

Messenger-rocks.com Pop-up Ads Removal – Safeguarding Against Deceptive Tactics

Searchmylinks.com Pop-up Removal: Eliminating Tech-Support Scam

TAGGED: Best Practices, Lazarus Ransomware, Malware, RaaS, Tech News

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Copy Link Print
Share
Previous Article Search4Word Browser Hijacker: Removal Guide and Prevention Tips
Next Article Revealing Farnetwork: Insights from a Unique “Job Interview” Process
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

Latest News

Ransomware
CACTUS Ransomware Exploits Qlik Sense Vulnerabilities
Ransomware
Colour Cure: Understanding and Preventing Browser Hijackers
Browser Hijackers
malicious website
The Risks of ourhugenewz[.]com and Similar Rogue Websites
Browser Hijackers
ransomware, stop/djvu
Elpy Ransomware: Unraveling the Threat and Prevention Measures
Ransomware
//

Check in Daily for the best technology and Cybersecurity based content on the internet.

Quick Link

  • ABOUT US
  • TERMS AND SERVICES
  • SITEMAP
  • CONTACT US

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

www.rivitmedia.comwww.rivitmedia.com
© 2023 • rivitmedia.com All Rights Reserved.
  • ABOUT US
  • TERMS AND SERVICES
  • SITEMAP
  • CONTACT US