KandyKorn is a sophisticated, memory-resident macOS remote-access trojan associated with a DPRK-linked intrusion set assessed to overlap with Lazarus Group activity. It was used against blockchain engineers at a cryptocurrency exchange through targeted Discord social engineering that lured victims to execute a purported cryptocurrency-arbitrage Python application. The multistage chain used Python downloaders and loader components to reflectively load KandyKorn into memory; a separate loader hijacked the legitimate Discord application to provide persistence.
KandyKorn daemonizes itself and communicates with command-and-control infrastructure using RC4-encrypted traffic and a custom handshake. It supports host and process enumeration, directory listing and recursive file statistics, file upload and download, directory archiving and exfiltration, secure file wiping, process termination, arbitrary command execution, and interactive pseudoterminal shell access. Operators can also retrieve or replace its command-and-control configuration and control its sleep interval. Its in-memory execution, encrypted communications, and anti-forensic file-wiping functionality complicate detection and forensic recovery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
KANDYKORN is the final reflectively loaded payload, a full-featured memory-resident RAT capable of encrypted C2, system enumeration, file transfer, compression and exfiltration, process killing, and interactive shell commands.
Given this execution flow and SugarLoader’s historical role in retrieving the KANDYKORN malware, it is likely that the final payload in the chain would be KANDYKORN or another fully-featured backdoor.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
resp_cmd_create spawns a shell on the system and communicates with it via a pseudoterminal.
Python scripts were used to drop malware that hijacked the host’s installed Discord app... Watcher.py checks the local Python version and downloads and executes testSpeed.py. The script downloads and executes another Python script, FinderTools.
SUGARLOADER uses this to retrieve and execute the KANDYKORN remote access trojan in-memory via NSCreateObjectFileImageFromMemory and NSLinkModule.
In the previous post, we analyzed how LaunchAgents work... LaunchAgents are great, but they have a flaw: macOS likes to scream about them with a “Background Items Added” notification... While their primary persistence was a LaunchAgent, they used shell configuration hijacking as a failsafe.
Today, I’ll talk about shell environment hijacking trick... The two most interesting files for us are: ~/.zshrc - executed for interactive shells... ~/.zshenv - executed for every instance of zsh... So, the main trick: we append a command to run our malware at the end of these files.
In the previous post, we analyzed how LaunchAgents work... LaunchAgents are great, but they have a flaw: macOS likes to scream about them with a “Background Items Added” notification... While their primary persistence was a LaunchAgent, they used shell configuration hijacking as a failsafe.
Today, I’ll talk about shell environment hijacking trick... The two most interesting files for us are: ~/.zshrc - executed for interactive shells... ~/.zshenv - executed for every instance of zsh... So, the main trick: we append a command to run our malware at the end of these files.
The victim believed they were installing an arbitrage bot, a software tool designed to profit from cryptocurrency rate differences between platforms.
Watcher.py deletes the testSpeed.py immediately following its execution... resp_file_wipe overwrites file content to zero and deletes the file.
When the breakpoint is hit, the code will already be decrypted in memory... The configuration file is encrypted using RC4... read into memory and decrypted.
When the malware first connects to the C2 server during the initialization phase, a handshake must be validated to proceed.
resp_proc_list lists all running processes on the system along with their PID, UID and other information.
resp_basicinfo gathers information about the system such as hostname, uid, osinfo, and image path of the current process.
It supports two C2 servers, one as the main server, and the second one as a fallback.
Operating covertly, KANDYKORN employs a feature-rich multi-staged loader paired with a custom network protocol to facilitate a range of post-compromise activities.
Watcher.py... fetches content from [a] Google Drive URL... written into the testSpeed.py file. testSpeed.py... fetches another Python file... FinderTools... downloading and executing... .sld.
The main feature of CosmicDoor is that it communicates with the C2 server using the WSS protocol, and it provides remote control functionality such as receiving and executing commands... SneakMain... receives additional AppleScript commands and uses the osascript -e command to execute them.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sophisticated macOS implant used by Lazarus Group against blockchain engineers, with shell configuration hijacking used as a fallback persistence mechanism to re-download or re-execute the loader if the primary LaunchAgent persistence was removed.
Referenced as a malware family leveraged in related BlueNoroff macOS-targeting campaigns; this content does not provide functional details beyond being delivered by SUGARLOADER in prior activity.
Referenced as a DPRK-linked malware/tool in a cited resource only; no behavioral details are provided in the content itself.
Malware used in a DPRK-linked campaign targeting blockchain engineers at a crypto exchange platform.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.