HomeCryptoReplay of LABScon23: Analysis of macOS Components Utilized in North Korean Crypto-Heists

Replay of LABScon23: Analysis of macOS Components Utilized in North Korean Crypto-Heists

-


Uncovering North Korean APTs Targeting macOS Devices: A Deep Dive into Similarity Analysis of Mach-O Binaries and Linked Dynamic Libraries

In a groundbreaking presentation at LABScon 2023, Greg Lesnewich of Proofpoint delved into the world of North Korean APTs targeting macOS devices. With a focus on similarity analysis of Mach-O binaries and linked dynamic libraries, Lesnewich provided researchers with new techniques for hunting down these increasingly active threats.

While many state-aligned threats have explored macOS malware, North Korea has shown a particular dedication to compromising Apple’s desktop operating system for both espionage and financial gain. The world of macOS malware analysis is a complex and exciting space, with most discussions focusing on functionality and capability rather than how to find more similar samples. Analysts often rely on string searching, making the process more challenging compared to analyzing Windows executables.

Lesnewich’s talk introduced easy pivots for Mach-O files, using North Korean samples as a case study. He guided the audience through the North Korean clusters using Mach-O samples, illustrating how these clusters intersect and how their families relate to one another. By demonstrating simple pivots, Lesnewich showed how analysts can link a group’s families together more effectively.

Greg Lesnewich, a senior threat researcher at Proofpoint specializing in tracking malicious activity linked to North Korea, brought his expertise in threat intelligence and incident response to the presentation. With a background in building threat intelligence programs for Fortune 50 financial organizations, Lesnewich provided valuable insights into the world of North Korean cyber threats.

LABScon 2023, hosted by SentinelOne’s research arm, SentinelLabs, is a premier cybersecurity conference that brings together top minds in the field. The event offers an immersive experience for cybersecurity professionals to stay updated on the latest trends and techniques in the industry.

For those interested in staying informed about LABScon 2024 and future developments in cybersecurity, be sure to follow the latest updates from SentinelLabs.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.

LATEST POSTS

Binance and KuCoin Partner with India’s Financial Intelligence Unit as Crypto Reputation Grows

India's FIU Approves Binance and KuCoin as First Offshore Crypto Entities India's anti-money laundering unit has approved offshore crypto entities Binance and KuCoin, marking a...

Inside Crypto’s ‘KOL’ Economy: Influencer-Investors Receive Benefits for Promoting Tokens

The Rise of KOLs in Crypto Fundraising: How Influencers are Shaping the Future of Investment in Cryptocurrency The Rise of KOLs: How Influencers Are Shaping...

Binance secures approval from FIU to resume operations in India

Binance Receives Approval to Offer Services in India from FIU Global cryptocurrency exchange Binance has received approval from the Indian Financial Intelligence Unit (FIU) to...

Upgrade to Dencun Breaks Ethereum’s Status as ‘Ultra-Sound Money’

The Impact of the Dencun Upgrade on Ethereum's Status as "Ultra-Sound Money" The latest report from crypto analytics firm CryptoQuant has raised concerns about Ethereum's...

Most Popular