North Korea’s Lazarus Group has used a backdoored PDF reader app SwiftLoader to deploy KANDYKORN macOS malware in an attempt to avoid detection. The group has also used SwiftLoader stager variants pretending to be the EdoneViewer executable for KANDYKORN RAT retrieval. These actions illustrate the increasing integration of tools and techniques used by North Korean cyber threat operations.

Trojanized Gaming Tools Spread Java-Based RAT via Browser and Chat Platforms – The Hacker News
Trojanized Gaming Tools Spread Java-Based RAT via Browser and Chat Platforms The Hacker News


