FILTERING BY: CLEAR FILTER

DPRK Campaign: Fake Zoom and Chrome Installers Deploy .NET Downloader and Overlord RAT on macOS

North Korean (DPRK) threat actors, specifically linked to the FlexibleFerret malware family, are targeting macOS environments through fraudulent Zoom and Google Chrome installers. The campaign leverages a novel .NET-based downloader on macOS to facilitate the deployment of the Overlord Remote Access Trojan (RAT). By utilizing sophisticated social engineering, including deepfake-enhanced video calls, the actors bypass Gatekeeper and macOS security prompts to establish persistence via LaunchAgents and LaunchDaemons. Once installed, the Overlord RAT provides full remote command execution, credential harvesting, and systematic file exfiltration, demonstrating a strategic shift toward using cross-platform frameworks to compromise high-value Unix-based endpoints.


LINK COPIED TO CLIPBOARD