Make a Living ClubMake a Living Club
  • Home
  • News
  • Business
  • Finance
  • Investing
  • Markets
    • Stocks
    • Commodities
    • Crypto
    • Forex
  • More
    • Economy
    • Politics
    • Real Estate
Trending Now

Box Q3: Limited Alpha Ahead (NYSE:BOX)

December 5, 2025

John Wiley & Sons, Inc. (WLY) Q2 2026 Earnings Call Transcript

December 4, 2025

General Motors Company (GM) Presents at UBS Global Industrials and Transportation Conference Transcript

December 3, 2025

Verizon: Not A Value Trap, The Math Works (NYSE:VZ)

December 2, 2025

John Hancock Multimanager 2015 Lifetime Portfolio Q3 2025 Commentary

December 1, 2025

BitMine Immersion: Major Test Passed So Far (NYSE:BMNR)

November 30, 2025
Facebook Twitter Instagram
  • Privacy
  • Terms
  • Press
  • Advertise
  • Contact
Facebook Twitter Instagram
Make a Living ClubMake a Living Club
  • Home
  • News
  • Business
  • Finance
  • Investing
  • Markets
    • Stocks
    • Commodities
    • Crypto
    • Forex
  • More
    • Economy
    • Politics
    • Real Estate
Sign Up for News & Alerts
Make a Living ClubMake a Living Club
Home » MacOS Malware KandyKorn Targets Crypto Owners
Crypto

MacOS Malware KandyKorn Targets Crypto Owners

Press RoomBy Press RoomNovember 4, 2023
Facebook Twitter Pinterest LinkedIn WhatsApp Email
Source: Pexels

A new MacOS malware, known as KandyKorn and linked to the notorious Lazarus Group, has recently been identified. The malware was discovered by the Elastic Security Labs.

According to an official report published by the blockchain security firm, KandyKorn relies on social engineering tactics, deceiving victims into installing a malicious ZIP file named “Cross-platform Bridges.zip.”

On the outside, this ZIP file appears to be an arbitrage artificial intelligence (AI) bot designed to assist users in generating yield automatically.

Meanwhile, on the inside, the malicious file downloads 13 Python-based modules that collaborate to retrieve user data and information illicitly.

Providing context on how efficient this virus is, the Elastic Security Labs noted that it operates clandestinely, and users are often unaware of events unfolding behind the scenes.

This malware then accesses an affected computer’s directory listing, uploads and downloads files automatically, deletes, processes termination, and executes commands.

To achieve this, the malicious malware is shared on Discord channels by the hackers who present themselves as community moderators. This fosters trust, leading users to download the malicious ZIP file, which subsequently infects and takes control of their laptops.

The DPRK was so excited about Halloween, they got a head start on passing out candy. Check out REF7001, AKA KANDYKORN – a malware distributed in cryptocurrency servers on Discord: https://t.co/ZJ1r92Yhvf#malware #threatdiscovery #cryptocurrency #discord #ElasticSecurityLabs

— Elastic Security Labs (@elasticseclabs) October 31, 2023

Expressing concern about the potential impact of the KandyKorn malware on Mac and iOS devices, the Elastic Security Labs team stated that the technique it is deploying is unusual.

This technique allows the malware to persistently bombard the targeted device through a process called execution flow hijacking.

KandyKorn is now a favored malware by the Lazarus Group, according to the report by Elastic Security Labs.

The anonymous group of hackers linked with the Democratic People’s Republic of North Korea (DPKR) has taken a strong interest in the crypto space in the last couple of years.

So far, the Lazarus Group has stolen more than a billion dollars from the nascent industry and has relied on cryptocurrency mixing platforms to harvest their illicit gains.

KandyKorn’s growing presence further highlights the growing level of sophisticated tools these hacking groups now rely on to siphon investors’ digital funds.

However, KandyKorn has not been the only actor in a vast ecosystem of viruses. The popular Telegram bot, Unibot, was also exploited upwards of $560,000 a few days earlier.

.@TeamUnibot seems exploited, the exploiter transfers memecooins from #unibot users and is exchanging them for the $ETH right now.

The current exploit size is ~$560K

Exploiter address:https://t.co/ysyTmgUAit pic.twitter.com/MF85Fdk892

— Scopescan (🪬 . 🪬) (@0xScopescan) October 31, 2023

According to a tweet by Scopescan on X (formerly Twitter), the exploiter traded regular meme coins from Unibot users for the Ether token.

State-Sponsored Hacking Terrorism

In recent months, global attention has been firmly fixed on the cryptocurrency sector. The primary concern revolves around the ease with which certain groups can employ advanced tools to move funds illicitly with little detection.

While various hacking groups operate in this landscape, the Lazarus Group has earned notoriety as one of the most prominent state-sponsored cyber threat groups within the crypto space.

However, their activities extend beyond the crypto space, as they have recently turned their attention to software companies.

At #TheSAS2023, our experts unveiled a sophisticated APT campaign by the #Lazarus group.

This campaign targets organizations worldwide through legitimate software designed to encrypt web communications using digital certificates.

Read our full report ⇒ https://t.co/zQ9okvUxyc pic.twitter.com/QtxkZprj7b

— Kaspersky (@kaspersky) October 27, 2023

The Kaspersky team recently unveiled a series of cyber attacks by the Lazarus Group. According to a report, the cyber threat group created legitimate software designed to encrypt web communications using digital signatures from the computer networks of organizations.

This enables them to retrieve data, break through firewalls, and upload or download required files and systems.


Enter your email for our Free Daily Newsletter

A quick 3min read about today’s crypto news!



Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Articles

'Fundamental Shift' in Traditional Bitcoin Market Cycle May Be on the Horizon

Crypto October 3, 2024

FTX/Alameda Unstakes Over $1B in Solana – Is a Major Price Shift Coming?

Crypto September 14, 2024

Blockchain News

Crypto May 30, 2024

Crypto Whales Are Stockpiling This New Dog Coin – Is It the Next Dogecoin?

Crypto May 29, 2024

Shiba Inu Price Prediction as Investor Turns $2,625 into $1.1 Million – Another Major Rally Starting?

Crypto May 28, 2024

Crypto Experts Pile Into New Solana Project – Could It Be the Next Big Thing?

Crypto May 27, 2024
Add A Comment

Leave A Reply Cancel Reply

Latest News

John Wiley & Sons, Inc. (WLY) Q2 2026 Earnings Call Transcript

December 4, 2025

General Motors Company (GM) Presents at UBS Global Industrials and Transportation Conference Transcript

December 3, 2025

Verizon: Not A Value Trap, The Math Works (NYSE:VZ)

December 2, 2025

John Hancock Multimanager 2015 Lifetime Portfolio Q3 2025 Commentary

December 1, 2025

BitMine Immersion: Major Test Passed So Far (NYSE:BMNR)

November 30, 2025
Trending Now

United Natural Foods Q1 Preview: Doesn’t Seem Like An Exciting Opportunity Right Now

November 28, 2025

The housing crisis is pushing Gen Z into crypto and economic nihilism

November 28, 2025

Voya Infrastructure, Industrials And Materials Fund Q3 2025 Commentary

November 27, 2025

Subscribe to Updates

Get the latest sports news from SportsSite about soccer, football and tennis.

Make a Living is your one-stop news website for the latest personal finance, investing and markets news and updates, follow us now to get the news that matters to you.

We're social. Connect with us:

Facebook Twitter Instagram YouTube LinkedIn
Topics
  • Business
  • Economy
  • Finance
  • Investing
  • Markets
Quick Links
  • Cookie Policy
  • Advertise with us
  • Get in touch
  • Submit News
  • Newsletter

Subscribe to Updates

Get the latest finance, markets, and business news and updates directly to your inbox.

2025 © Make a Living Club. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Press Release
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.