InjectWithDyld is a macOS C++ binary loader observed in a June 2025 intrusion against a cryptocurrency foundation and attributed with high confidence by Huntress to the North Korean threat group TA444 / BlueNoroff. It was downloaded by the Root Troy V4 Go backdoor as part of a multi-stage malware set delivered after Telegram- and fake Zoom-themed social engineering involving a malicious AppleScript disguised as a Zoom extension. InjectWithDyld decrypts two additional embedded payloads using AES keys derived via PBKDF from the password "gift123$%^". It supports process injection on macOS using task_for_pid and mach_vm APIs, and was used alongside a benign Swift application called Base App that remained alive for later injection. One decrypted payload was a Nim implant referred to as Trojan 1, which communicated with the C2 server wss://firstfromsep[.]online/client. The loader also included an anti-forensic "--d" mode that overwrote files in the current directory with zeros. In reporting on the same intrusion, InjectWithDyld was described as a loader that drops the benign Base App and another payload, and as one of eight malicious binaries recovered from the victim host. The broader campaign targeted cryptocurrency organizations and used infrastructure including support[.]us05web-zoom[.]biz and firstfromsep[.]online.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
InjectWithDyld (a): a binary loader written in C++ that is downloaded by Root Troy V4. It will decrypt two additional payloads.
InjectWithDyld (a): a binary loader written in C++ that is downloaded by Root Troy V4. It will decrypt two additional payloads.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
C++ loader used in the infection chain to facilitate process injection and deploy additional implants (including a Nim implant) on macOS.
A C++ loader that derives AES keys from an operator-supplied password, decrypts embedded payloads, and injects them into another process using Mach task APIs. It also supports an antiforensic mode that overwrites files with zeros.
A loader used to drop a benign Base App and an additional payload as part of the BlueNoroff infection chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.