ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Crypto

North Korea-Linked Lazarus Group Unleashes New KandyKorn macOS Malware in Targeted Assaults on Blockchain Engineers

Kyle by Kyle
November 5, 2023
in Crypto, Malware
Reading Time: 2 mins read
Lazarus Group targets Blockhain Crypto engineers
Share on FacebookShare on Twitter

The Lazarus APT group, which has ties to North Korea, has recently come to the attention of security experts at Elastic Security Labs for deploying a novel macOS malware named KandyKorn in targeted attacks against blockchain engineers. Elastic Security Labs, a prominent cybersecurity research entity, unveiled this development.

You might also like

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Betterment Investment Users Targeted by “Triple Crypto” Scam Notification

According to the findings by Elastic Security Labs, KandyKorn represents a sophisticated implant boasting a diverse range of capabilities, enabling it to monitor, interact with, and elude detection. Notably, KandyKorn employs reflective loading, a method of direct-memory execution that possesses the potential to evade conventional detection mechanisms. Elastic Security Labs, the institution that identified and analyzed this emerging threat, underscored these details in their report.

In the course of these cyber operations, threat actors assumed the guise of members from the blockchain engineering community within a public Discord channel regularly used by community members. Their stratagem involved deceiving unsuspecting victims into downloading and decompressing a ZIP archive labeled “Cross-Platform Bridges.zip,” which concealed malicious Python code masked as an arbitrage bot. Arbitrage bots are tools employed by users to exploit variations in cryptocurrency rates across different platforms.

The overarching goal of the attack chain was to compromise the targeted system with the KandyKorn macOS malware. To achieve this objective, a sequence of malicious code components was utilized:

  1. Stage 0 (Initial Compromise) – “Watcher.py”
  2. Stage 1 (Dropper) – “testSpeed.py” and “FinderTools”
  3. Stage 2 (Payload) – “.sld” and “.log” files, collectively referred to as “SUGARLOADER”
  4. Stage 3 (Loader) – Deceptive “Discord” application (fake) – “HLOADER”
  5. Stage 4 (Payload) – The actual KandyKorn malware

Upon decompression of the aforementioned archive, a “Main.py” script and a folder named “order_book_recorder,” housing 13 Python scripts, were revealed. The SUGARLOADER component established a connection with a command and control (C2) server to download KandyKorn and execute it directly within the system’s memory.

Elastic Security researchers managed to trace this campaign back to April 2023, primarily through the use of the RC4 key for encrypting the SUGARLOADER and KandyKorn C2 communications.

KandyKorn, as a malware, boasts a diverse set of functionalities, including information harvesting, directory listing and process execution, file downloads and uploads, archiving directories and exfiltrating data, process termination, terminal command execution, shell spawning, server configuration retrieval, sleep mode, and program termination.

North Korea-linked threat actors persist in their relentless targeting of cryptocurrency-related organizations, a strategy aimed at circumventing international sanctions and financing their military endeavors.

The report concludes, “The DPRK, through units such as the LAZARUS GROUP, continues to target crypto-industry businesses with the goal of stealing cryptocurrency in order to circumvent international sanctions that hinder the growth of their economy and ambitions. In this intrusion, they targeted blockchain engineers active on a public chat server with a lure designed to speak to their skills and interests, with the underlying promise of financial gain. The infection required interactivity from the victim that would still be expected had the lure been legitimate.”

Elastic Security warns that this campaign remains active and emphasizes that the threat actors behind it are continually refining their tactics, techniques, and procedures to ensure their continued effectiveness.

Tags: Lazarus
Previous Post

Microsoft Exchange Faces Critical Zero-Day Vulnerabilities: Trend Micro’s ZDI Discloses Four Flaws

Next Post

Meta’s Facebook Ad Network Targeted by Malware Scam: NodeStealer Threat Exposed

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026
Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

Betterment Investment Users Targeted by “Triple Crypto” Scam Notification

January 11, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

December 18, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.