TechRadar News.
Technology

Counterfeit macOS Installers Spread Credential‑Harvesting RAT Tied to North Korean Operation

Counterfeit macOS Installers Spread Credential‑Harvesting RAT Tied to North Korean Operation

Researchers in the security field have detected a fresh batch of harmful macOS installers posing as well‑known apps, which in reality drop a credential‑stealing remote‑access trojan. They catalogued fourteen separate disk images and installer packages, each designed to resemble genuine software yet covertly infect the user’s machine.

These harmful bundles were shared across multiple internet venues, such as file‑sharing platforms and discussion boards where macOS tools are frequently traded. When a victim executes the installer, the payload drops a backdoor that siphons stored passwords, authentication tokens and other confidential information, forwarding it to command‑and‑control servers operated by actors associated with the Democratic People’s Republic of Korea.

Code analysis uncovered a uniform set of markers: identical obfuscation methods, common encryption keys, and a shared network‑communication routine that reaches servers located in regions frequently exploited by North Korean cyber groups. These technical signatures match earlier operations linked to the DPRK’s Lazarus Group, known for attacking both Windows and macOS platforms for espionage and monetary objectives.

Although macOS has historically been seen as a less appealing target than Windows, the emergence of cross‑platform malware shows threat actors widening their scope. This fresh trojan not only extracts credentials but also grants remote‑control functions, enabling operators to run arbitrary commands, deploy extra software, or move laterally to other machines on the network.

Specialists caution that the misleading names of the installers—frequently imitating popular productivity or developer tools—pose a heightened risk to non‑technical users who might trust the file’s look. They recommend confirming the origin of any macOS installer, favoring official app stores, and activating Gatekeeper’s more stringent verification to block unsigned applications.

Cybersecurity companies are issuing advisories and refreshing detection signatures so endpoint protection tools can spot the malicious disk images. As the operation progresses, analysts anticipate the actors will hone their distribution tactics, possibly using social‑engineering ploys or compromised sites to extend their influence. Ongoing monitoring and swift patching stay essential defenses against this nascent macOS danger.

TechRadar Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related