Huntress researchers provide a detailed technical analysis of a macOS intrusion by North Korean APT group BlueNoroff (TA444). The attack began with a social engineering lure via Telegram, directing a cryptocurrency foundation employee to a fake Zoom meeting where deepfakes of company leadership convinced them to download a malicious AppleScript disguised as a Zoom extension. The intrusion chain deployed 8 distinct malware components including: a Nim-based persistent implant (Telegram 2), a Go backdoor (Root Troy V4/remoted), a C++ loader (InjectWithDyld) that uses macOS debugging entitlements for process injection via Mach ports, a keylogger/screen recorder written in Objective-C (XScreen/keyboardd), and a Go-based cryptocurrency infostealer (CryptoBot/airmond) targeting 23 browser wallet extensions including MetaMask, Phantom, and Binance. The post includes full IOCs, C2 infrastructure, file hashes, and mitigation guidance for meeting-application social engineering attacks.

19m read timeFrom huntress.com
Post cover image
Table of contents
SummaryInitial accessTechnical analysisIdentifying and mitigating Meeting application social engineeringConclusionIOCs