Elastic Security Labs identified a DPRK-attributed campaign, tracked as REF7001, that targeted blockchain engineers through Discord-distributed Python cryptocurrency-arbitrage bots. The multi-stage macOS infection chain downloaded SUGARLOADER, hijacked the Discord application for persistence using HLOADER, and reflectively loaded the final KANDYKORN payload in memory.
KANDYKORN is a memory-resident remote-access trojan that uses encrypted command-and-control communications and supports reconnaissance, interactive shell commands, file transfers, archiving and exfiltration, process termination, and configuration changes. Elastic assessed that the operation overlaps with the Lazarus Group based on shared infrastructure, code-signing patterns, detection logic, and tradecraft; a shared RC4 key indicated activity dating to at least April 2023.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Reddit posts reported fake recruiting contacts using similarly structured malicious URLs and Python speed-test coding challenges, consistent with the infrastructure and lures used in the campaign.
A DPRK-attributed intrusion set tracked as REF7001 began targeting blockchain engineers at a cryptocurrency exchange platform with a malicious Python cryptocurrency-arbitrage bot delivered through Discord. Elastic later traced the campaign to April 2023 through an RC4 key shared by SUGARLOADER and KANDYKORN.
Elastic Security Labs disclosed the REF7001 intrusion chain, in which a Discord-delivered Python lure downloaded SUGARLOADER, hijacked the macOS Discord application for persistence through HLOADER, and reflectively loaded the memory-resident KANDYKORN RAT. Elastic assessed overlaps with Lazarus Group based on infrastructure, code-signing patterns, detections, and techniques, and said the campaign remained active.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 25 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.