A new Apple macOS malware, named “KandyKorn,” has been discovered, and it’s associated with the notorious North Korean hacking group, Lazarus. This malware has been specifically designed to target blockchain engineers working for cryptocurrency exchange platforms.
KandyKorn malware targets Crypto professionals
KandyKorn is a covert malware that can do various things like stealing data, listing directories, transferring files, deleting securely, stopping processes, and running commands. Elastic Security Labs conducted a thorough analysis to understand how this malware gets into users’ computers.
The attackers behind KandyKorn initially distributed Python-based modules through Discord channels, posing as community members. They used social engineering tactics to deceive community members into downloading a malicious ZIP archive named “Cross-platform Bridges.zip.”

This file pretended to be a money-making bot but, when opened, it secretly imported 13 bad parts that stole and messed with sensitive data.
How KandyKorn spread among Crypto communities?
The report from Elastic Security Labs highlights a previously unseen technique employed by the threat actors known as “execution flow hijacking,” which enables the malware to maintain persistence on macOS.
Lazarus Group’s financial motives in the Crypto industry
Lazarus, the North Korean hacking group behind KandyKorn, is mostly focused on making money in the cryptocurrency field. They do some other stuff too, but their main goal is financial gain. KandyKorn’s existence highlights their skill in creating tricky malware for Apple computers.
Recently, a similar incident was reported by Todayq News on October 31, 2023, an exploit targeting Unibot, a popular Telegram bot used for trading on the decentralized exchange Uniswap. Blockchain analytics firm Scopescan identified the ongoing hack and alerted Unibot users, which was later confirmed by an official source.
Related Article: North Korean Lazarus Group’s ‘Kandykorn’ malware strikes Crypto exchanges
Unibot has taken responsibility for the situation and announced that they experienced a token approval exploit from their new router. As a response, they temporarily paused the router to contain the issue. Additionally, Unibot has committed to compensating all users who suffered financial losses due to the contract exploit.
This news shows that the cryptocurrency community faces growing cybersecurity challenges. Advanced malware like KandyKorn highlights the need for constant vigilance and strong security measures to protect digital assets and sensitive information in the crypto world.
