PULSE NAME
DriverFixer0428 macOS Credential Stealer
WHITE PetrP.73 2025-12-29 Modified: 2025-12-29
3
IOCs
LOW VOLUME
DriverFixer0428 is a sophisticated credential-stealing malware targeting macOS, associated with North Korea's Contagious Interview campaign. Static and dynamic analysis reveal that this malware masquerades as a legitimate system utility, employing deceptive social engineering dialogs that mimic genuine macOS prompts and Google Chrome permission requests to harvest user credentials. The extracted credentials are exfiltrated through Dropbox's cloud storage API, showcasing a seamless integration into legitimate services to facilitate data theft. The malware demonstrates advanced evasion techniques, notably through its adept handling of virtual machine (VM) detection. Analysis using LLDB found that rather than relying on static string comparisons, DriverFixer0428 executes runtime API checks to identify whether it is operating within a virtualized environment. This approach includes querying system APIs such as `sysctlbyname` and IOKit registry queries.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
DriverFixer0428
Indicators of Compromise (3)
All FileHash-SHA256 YARA domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 9aef4651925a752f580b7be005d91bfb1f9f5dd806c99e10b17aa2e06bf4f7b5 2025-12-29
YARA 57998b97e5c30eb766f4bda0ec799662d080ff2f DPRK DriverFixer credential stealer 2025-12-29
domain kern.secure 2025-12-29