TF-MAL-osx.kandykorn
📛 Threat Title
Malware family: KANDYKORN
Description
ThreatFox malware family `osx.kandykorn`. Printable name: KANDYKORN.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.kandykorn
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.kandykorn
IOC database
- Type
- domain
- Value
osx.kandykorn- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.kandykorn
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.kandykorn
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:intel.dev.threatlabs.protect.jamfcloud.com
KANDYKORN is a full-featured remote access trojan (RAT) capable of encrypted command and control (C2) communication, system enumeration, data exfiltration, terminating processes, and executing arbitrary system commands or payloads.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the KANDYKORN malware family including references, samples and yara signatures.
-
web:securityaffairs.com
North Korea-linked Lazarus group is using new KandyKorn macOS Malware in attacks against blockchain engineers. North Korea-linked Lazarus APT group were spotted using new KandyKorn macOS malware in attacks against blockchain engineers, reported Elastic Security Labs. " KandyKorn is an advanced implant with a variety of capabilities to monitor, interact with, and avoid detection. It utilizes […]
-
web:www.broadcom.com
A new campaign dubbed REF7001 targeted at macOS users has been reported in the wild. The attack chain is multi-staged and involves the initial compromise through Python scripts, delivery of SugarLoader and HLoader malware variants and the final infection with the KandyKorn payload. The KandyKorn malware has capabilities for data collection and ex-filtration from the infected endpoint. The ...
-
web:www.elastic.co
Elastic catches DPRK passing out KANDYKORN Elastic Security Labs exposes an attempt by the DPRK to infect blockchain engineers with novel macOS malware .
-
web:www.enigmasoftware.com
KANDYKORN , serving as the ultimate payload, is a fully-featured memory-resident Remote Access Trojan (RAT) with inherent capabilities for file enumeration, running supplementary malware , exfiltrating data, terminating processes, and executing arbitrary commands.
-
web:www.fortinet.com
FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.
-
web:www.pcrisk.com
KandyKorn malware overview KandyKorn is a highly sophisticated final-stage payload utilized as a tool that enables threat actors to infiltrate and extract data from the compromised computer. Operating covertly in the background as a daemon, KandyKorn patiently awaits commands from the Command and Control (C2) server.
-
web:www.researchgate.net
Prevention and detection of eBPF-based malware is also explored, with the goal of providing organizations or legitimate users of eBPF techniques to harden their systems against eBPF-based malware ...
-
web:www.securityweek.com
The notorious North Korean hacking group Lazarus has used new macOS and Windows malware in recent attacks, security researchers warn. In one of the attacks, blockchain engineers at a cryptocurrency exchange platform were targeted with a Python application designed to provide initial access ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.