← Back to Pulse Feed
PULSE DETAIL
DriverFixer0428 is a sophisticated credential-stealing malware targeting macOS, associated with North Korea's Contagious Interview campaign. Static and dynamic analysis reveal that this malware masquerades as a legitimate system utility, employing deceptive social engineering dialogs that mimic genuine macOS prompts and Google Chrome permission requests to harvest user credentials. The extracted credentials are exfiltrated through Dropbox's cloud storage API, showcasing a seamless integration into legitimate services to facilitate data theft.
The malware demonstrates advanced evasion techniques, notably through its adept handling of virtual machine (VM) detection. Analysis using LLDB found that rather than relying on static string comparisons, DriverFixer0428 executes runtime API checks to identify whether it is operating within a virtualized environment. This approach includes querying system APIs such as `sysctlbyname` and IOKit registry queries.
MITRE ATT&CK & Malware Families
Indicators of Compromise (3)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 9aef4651925a752f580b7be005d91bfb1f9f5dd806c99e10b17aa2e06bf4f7b5 | — | 2025-12-29 | |
| YARA | 57998b97e5c30eb766f4bda0ec799662d080ff2f | DPRK DriverFixer credential stealer | 2025-12-29 | |
| domain | kern.secure | — | 2025-12-29 |