# SpectralBlur macOS backdoor tied to DPRK's TA444

Published: 2024-01-04 · Severity: medium · Sectors: financial-services
Canonical: https://vorant.io/reports/ffe84e23-4a2f-539d-bf74-494b697141f6/spectralblur-macos-backdoor-tied-to-dprk-s-ta444

> Researchers detailed SpectralBlur, a macOS backdoor linked to DPRK-affiliated TA444/BlueNoroff, that mirrors capabilities seen in the KandyKorn malware family.

Objective-See performed a deep technical triage of SpectralBlur, a macOS backdoor first flagged publicly by researcher Greg Lesnewich in early January 2024. The malware, an unsigned x86_64 Mach-O binary observed under filenames .macshare and mac.jpg, supports typical backdoor functionality including file upload/download, shell command execution via a pseudo-terminal, configuration management, file deletion (with secure overwrite), sleep/hibernate, and process restart/kill, all driven by commands received from a C2 server over an encrypted channel using a custom stream cipher (xcrypt).

Analysis found the sample uses several anti-analysis techniques such as forking, spawning pseudo-terminals via posix_openpt/grantpt, and multiple process forks/execs, likely to complicate detection and dynamic analysis. The sample was first submitted to VirusTotal in August 2023 from Colombia and was undetected by any AV engine at that time, with only ESET flagging it after a rescan months later. Researchers noted structural and functional overlaps with KandyKorn, a known DPRK-linked macOS malware family previously documented by Elastic, though differences suggest SpectralBlur may have been developed by a separate team with similar operational requirements.

Attribution ties SpectralBlur to TA444, also known as BlueNoroff, a North Korean state-sponsored threat actor historically associated with cryptocurrency theft and financial-sector targeting. No specific victims or campaign name were disclosed in this technical writeup; the focus is on malware capability analysis and family linkage rather than active in-the-wild targeting details.

## Mentioned in this report

- Threat actors: TA444
- Malware: KANDYKORN, SpectralBlur

Source reporting: https://objective-see.org/blog/blog_0x78.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ffe84e23-4a2f-539d-bf74-494b697141f6/spectralblur-macos-backdoor-tied-to-dprk-s-ta444.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
