DPRK-linked BlueNoroff used macOS malware with novel persistence
Security Affairs
NOVEMBER 7, 2024
” The attackers, linked to BlueNoroff and past RustBucket campaigns, used fake cryptocurrency news emails and a malicious app disguised as a PDF. The application bundle has the bundle identifier Education.LessonOne and contains a universal architecture (i.e., arm64 and x86-64) Mach-O executable named LessonOne.”
Let's personalize your content