s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.spectral_blur

📛 Threat Title

Malware family: SpectralBlur

Category: SpectralBlur First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.spectral_blur`. Printable name: SpectralBlur.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    This backdoor exhibits similarities with the KANDYKORN malware family associated with North Korean threat actors. SpectralBlur is a moderately capable backdoor, enabling file upload/download, shell execution, configuration updates, file deletion, hibernation, or sleep, controlled by commands from a command-and-control server.

  • web:blog.polyswarm.io

    Lesnewich notes he originally found SpectralBlur in August 2023 and that SpectralBlur appears to overlap with KandyKorn, another malware family attributed to Stardust Chollima. While SpectralBlur is not a sophisticated backdoor, it does continue the trend of Stardust Chollima targeting MacOS systems.

  • web:lazarus.day

    Contents As 'Sharing is Caring' I've uploaded a sample of the malware SpectralBlur .zip to our public macOS malware collection. The password is: infect3d Not three days into 2024 Greg Lesnewich tweeted the following: #100DaysofYARA day 03 - talking SpectralBlur , a MacOS (and other OS 🤫) backdoor linked to TA444/Bluenoroff, that I suspect is a cousin of the KandyKorn family our pals at ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the SpectralBlur malware family including references, samples and yara signatures.

  • web:moonlock.com

    A new backdoor malware known as SpectralBlur could put macOS users at risk. Here's everything we know about this cybersecurity threat so far.

  • web:thehackernews.com

    Cybersecurity researchers have discovered a new Apple macOS backdoor called SpectralBlur that overlaps with a known malware family that has been attributed to North Korean threat actors. " SpectralBlur is a moderately capable backdoor that can upload/download files, run a shell, update its ...

  • web:www.broadcom.com

    SpectralBlur BlueNoroff, also known as TA444, remains active and continues to introduce new MacOS malware families. In a recent campaign, the threat actor has been reported distributing a MacOS backdoor dubbed SpectralBlur . The SpectralBlur malware backdoor incorporates typical features such as file upload and download, file deletion, shell execution, and configuration updates. These actions ...

  • web:www.securemac.com

    High Description SpectralBlur is a hybrid threat that maintains upgradable backdoor features that can receive, transmit, and modify files and commands from a remote server. SpectralBlur Threat Removal MacScan can detect and remove SpectralBlur Hybrid Threat from your system, as well as provide protection against other security and privacy threats.

  • web:www.securityweek.com

    Security researchers have dived into the inner workings of SpectralBlur , a new macOS backdoor that appears linked to the recently identified North Korean malware family KandyKorn. The observed SpectralBlur sample was initially uploaded to VirusTotal in August 2023, but remained undetected by the ...

  • web:www.techtimes.com

    Mac users should be careful about the latest malware threat since SpectralBlur can erase all your files without a trace. You won't have any second to think about how it infected your PC in the ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.