BlueNoroff, a well-known hacking group linked to North Korea's Lazarus, has introduced a new MacOS malware aimed at financial institutions. Researchers from Apple device management company Jamf discovered this malware, which was disguised as a legitimate cryptocurrency exchange.
The malicious payload communicates with a domain, swissborg[.]blog, controlled by the attackers. BlueNoroff is a threat actor that primarily targets cryptocurrencies, crypto startups, and financial organizations. The newly discovered MacOS crypto-malware is believed to be part of the RustBucket campaign. While it may appear simple, the malware is highly functional and is likely used at a later stage for various malicious activities. Researchers have named it "ObjCShellz."