North Korean Hackers Targeting Crypto Experts with KANDYKORN macOS Malware

Discussion in 'all things Mac' started by 1PW, Nov 1, 2023.

  1. 1PW

    1PW Registered Member

    Joined:
    Apr 2, 2010
    Posts:
    2,313
    Location:
    .
    State-sponsored threat actors from the Democratic People's Republic of Korea (DPRK) have been found targeting blockchain engineers of an unnamed crypto exchange platform via Discord with a novel macOS malware dubbed KANDYKORN.

    More… and...
     
    Last edited: Nov 1, 2023
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    And this is exactly why it's so important that the macOS firewall isn't broken! You could easily tackle this stuff with a firewall and anti-logger. And then I'm mainly talking about the last stage of this attack, although when the user fully trusts this app it gets more difficult of course. So my point is, never fully trust any app.

     
  3. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,100
    Location:
    Canada
    It looks like the macOS firewall is Off by Default.
     
  4. ProTruckDriver

    ProTruckDriver Registered Member

    Joined:
    Sep 18, 2008
    Posts:
    1,461
    Location:
    "An Apple a Day, Keeps Microsoft Away"
    That's one of the first things I turned on when I bought my iMac 7 years ago.

    Firewall.png
     
  5. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    This is what I never understood. But isn't this the case on Windows too? And then I'm talking specifically about outbound connections. Actually, I've just read in the article that this is indeed the case. The inbound connections are not so much of a problem because shouldn't the modem/router take care of this? But to block malware from phoning home, you obviously need outbound control. This is not clearly explained in the article, a missed opportunity.
     
  6. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,100
    Location:
    Canada
    Certainly a good idea, but of course outbound control is needed to control how apps and other programs connect, if that's what the user wants.

    In Windows, the firewall is enabled by default, but only to block incoming connections. The article inaccurately claims that Windows firewall does not block outgoing, but it can be set up to do so, just not in a user-friendly way unless a 3rd-party utility such as Windows Firewall Control is used.I don't use macOS so I don't know if its firewall can be set up to block outgoing connections. Of course as you mention, blocking incoming only, does nothing to stop apps or malware from phoning home on an outbound connection.
     
  7. 1PW

    1PW Registered Member

    Joined:
    Apr 2, 2010
    Posts:
    2,313
    Location:
    .
    Hello @wat0114

    This why 3rd party macOS apps such as LuLu, Little Snitch and others are strongly suggested for inclusion in your defense arsenal.

    In the case of Objective-see's LuLu, the user may specify and develop a custom block list containing the toxic URLs and IPs.

    HTH
     
    Last edited: Nov 21, 2023
  8. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,100
    Location:
    Canada
    That's good to know if ever I use macOS, I will check these out. Thanks!
     
  9. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Exactly, I wonder if ProTruckDriver knew about this? Radio Silence is another interesting outbound firewall, see link.

    And speaking of this particular attack, I'm not sure if KANDYKORN, which is the final payload, runs as a separate (child) process or not. Because only then could a firewall block the outbound connection. And I'm also not sure if it makes use of code injection, which is less common on macOS, but is possible.

    What I'm saying is, if this malware is a bit more sophisticated than thought, then you need a behavior blocker to block it from getting access to private files and to block it from bypassing the firewall. Problem is, on macOS there aren't that many behavior blockers available.

    https://radiosilenceapp.com
     
  10. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Well, the built-in firewall is a disaster so I always use Windows Firewall Control to manage it. I also use Tinywall as my third party firewall which doesn't depend on the built-in firewall and has a silent mode, because those alerts might drive you nuts.
     
  11. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.