North Korean Hackers Target macOS With New Crypto Malware

April 29, 2025
Palo Alto Networks Unit 42 uncovers a North Korean cyber campaign using a newly discovered macOS variant of Koi Stealer malware to target cryptocurrency developers through sophisticated social engineering tactics.
About the Author

Adva Gabay | MacOS Research Team Lead

Adva Gabay is the leader of the macOS research team for Cortex XDR, focusing on low-level research, coverage, and detection initiatives. Her experience includes low-level and network research across various operating systems, specializing in macOS, as well as reverse engineering and the development of research tools for these platforms.

About the Author

Daniel Frank | Threat Research Team Leader

Daniel Frank is the Threat Research Team Leader at Palo Alto Networks, with over a decade of experience. His core roles include researching emerging threats, reverse-engineering malware and threat hunting. Frank has showcased his research in different cybersecurity conferences over the years. He has a BSc degree in information systems.