Listen to this Post

A Chilling New Chapter in Cyber Espionage
A recent investigation has unveiled a sophisticated cyber-espionage campaign orchestrated by North Korea’s notorious state-backed hacking unit TA444, also known as BlueNoroff, STARDUST CHOLLIMA, and CageyChameleon. This campaign is specifically targeting the cryptocurrency sector by blending cutting-edge malware with psychological manipulation tactics. Leveraging advanced macOS-specific malware and highly convincing social engineering techniques, the attackers used fake video calls, weaponized calendar invites, and even deepfake technology to infiltrate and exfiltrate data from unsuspecting victims.
How the Campaign Unfolded
The attack began when a cryptocurrency foundation employee received a seemingly innocent message on Telegram from a stranger posing as a business associate. The message invited them to a meeting via a Calendly link, which masqueraded as a standard Google Meet invitation. In reality, the link redirected the user to a spoofed Zoom domain fully controlled by the threat actors. The fake meeting wasn’t empty either — it featured deepfake-generated avatars imitating real company executives, enhancing the illusion of legitimacy.
During the video session, the employee was instructed to install a “Zoom extension” to resolve microphone issues. This so-called extension was actually a malicious AppleScript file named zoom_sdk_support.scpt. The script appeared harmless at first glance, even opening a legitimate Zoom SDK page. However, hidden beneath layers of white space was obfuscated code that downloaded the real malware payload.
This payload initiated a multi-stage infection process. First, the malware verified the presence of Rosetta 2, ensuring compatibility with Apple Silicon devices. Then, it deployed several custom-built malware components. These included:
A persistent Nim-based loader (“Telegram 2”) that ensured hourly communication with the command-and-control (C2) servers.
A modular Go-based backdoor (“Root Troy V4” or “remoted”) with capabilities like remote code execution and stealthy operation during inactive hours.
A loader called “InjectWithDyld” that hijacked system processes using macOS debug entitlements.
Objective-C tools like “keyboardd” for screen recording, clipboard access, and keystroke logging.
A cryptocurrency-stealing infostealer (“CryptoBot”/”airmond”) that targeted browser wallets and extension credentials.
The attackers also deployed anti-forensics tactics, such as wiping shell history and log files, and used deceptive domains like support.us05web-zoom.biz and productnews.online to evade detection. These domains impersonated trusted platforms, making it harder for users and security tools to flag malicious activity. This incident shatters the long-standing myth that macOS is immune to state-sponsored malware and highlights the increasing interest of North Korean APTs in targeting the crypto industry for financial gain.
What Undercode Say:
Deepfake Tactics Signal a Psychological Turning Point
This campaign marks a disturbing leap in cyberattack sophistication. The introduction of deepfake avatars in real-time video calls isn’t just technically impressive — it’s psychologically manipulative. By simulating the visual presence of a company’s senior leadership, TA444 effectively lowered the victim’s guard. This isn’t just phishing, it’s performance art designed to deceive at a very high level.
Weaponizing Trust in Calendly and Google Meet
Calendly and Google Meet are widely trusted in the corporate world, especially in decentralized work environments like those in crypto. By spoofing these tools, the attackers exploited a comfort zone. This isn’t a generic phishing link in an email — it’s a carefully crafted illusion integrated into the rhythm of daily business operations. It’s weaponized normalcy.
Shift Toward macOS Attacks
macOS was once seen as a secure alternative to Windows, but that perception is rapidly eroding. This campaign illustrates that state-sponsored actors now develop malware specifically for Apple environments. The use of Rosetta 2 checks and Objective-C payloads shows that these attackers are well aware of modern macOS architecture and are tailoring their toolkits accordingly.
Complex Malware, Streamlined Execution
The use of AppleScript, Nim, Go, and Swift within one campaign showcases a multilingual malware ecosystem that can adapt and evolve. Each component served a precise role: persistence, remote control, data theft, process injection. The streamlined execution chain — from social engineering to full device compromise — was seamless, and that’s what makes it terrifying.
Crypto Remains a Prime Target
It’s no surprise that North Korean threat actors are going after crypto. Sanctions have made traditional financial systems inaccessible to the regime, so stolen cryptocurrency becomes a lifeline. The infostealer component, specifically engineered to extract wallet data from browser extensions, proves how targeted and financially motivated this operation really was.
Obfuscation and Anti-Forensics Raise the Bar
The malware didn’t just infect — it erased its tracks. By deleting shell histories and log files, it made post-incident investigations far more difficult. Combined with encrypted C2 communications and obscure TLDs, TA444 displayed a strong understanding of both offensive and defensive cybersecurity tactics.
Recommendations for Defenders
Companies in crypto and other high-value sectors need to evolve their defenses. Basic antivirus tools won’t cut it anymore. Endpoint detection and response (EDR) platforms, regular threat hunting, and employee training against advanced social engineering should become the norm. It’s no longer about preventing all attacks, but about detecting and responding to them before damage is done.
🔍 Fact Checker Results:
✅ The malware campaign was confirmed by Huntress Labs
✅ Multiple domains used were verified as C2 channels
✅ Deepfake avatars were documented as part of the attack
📊 Prediction:
🎯 Expect more APT groups to adopt deepfake tactics in cyber operations
🧠 macOS-specific malware will rise, challenging
💸 The crypto sector will remain a top target for financially motivated cyber-espionage campaigns
References:
Reported By: cyberpress.org
Extra Source Hub:
https://www.stackexchange.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2




