Malware attack techniques combined in new North Korean macOS intrusions
North Korea’s Lazarus Group has used a backdoored PDF reader app SwiftLoader to deploy KANDYKORN macOS malware in an attempt to avoid detection. The group has also used SwiftLoader stager variants pretending to be the EdoneViewer executable for KANDYKORN RAT retrieval. These actions illustrate the increasing integration of tools and techniques used by North Korean cyber threat operations.