How North Korean hackers are using crypto apps to target Apple Mac devices

Hackers associated with North Korea have installed disguised malware in Apple macOS systems by reportedly using Google's Flutter app development tool to bypass security measures.

November 13, 2024 / 17:03 IST
Story continues below Advertisement
Hackers target macOS
Hackers target macOS

North Korean hackers have reportedly developed a new malware that has evaded the stringent Apple security checks and embedded malware within Google’s Flutter applications. The hackers are reportedly using this app’s development tool to bypass security measures and infect Mac devices. Further, the hackers are targeting cryptocurrency-related businesses with multi-stage malware.

How hackers are using Google’s Flutter to target Mac users?

Story continues below Advertisement

According to a report by AppleInsider, researchers at Jamf Threat Labs have uncovered malware embedded in macOS devices that look harmless on the surface. However, using popular app-building tools, like Google’s Flutter, cybercriminals have bypassed typical security measures and made consumers download a fake PDF file via phishing emails allegedly providing vital information about cryptocurrency.

Starting in November 2024, Jamf Threat Labs researchers have discovered multiple apps on VirusTotal that appeared to completely bypass all antivirus scans yet showcased "stage one" functionality, connecting to servers associated with North Korean threat actors. In particular, one variant, hidden within a fake crypto exchange game and built with Google's Flutter, downloads malicious scripts to remotely control infected Mac devices.