Skip to main content
Mallory
Back to malware
MalwareUsed by 4 actors

CoreKitAgent

CoreKitAgent is a trojan/dropper component used in North Korea-linked macOS intrusion chains associated with Lazarus Group sub-cluster BlueNoroff and the broader NimDoor/DownTroy activity targeting Web3, cryptocurrency, tech, and venture capital victims. It has been observed in social-engineering campaigns in which targets are lured via Telegram into fake Zoom or Microsoft Teams meetings and prompted to run a malicious "SDK update" script. In reported chains, CoreKitAgent is dropped or launched by Nim-based executables and is used in DownTroy v2 as a dropper to launch the Nimcore loader, which then launches AppleScript-based DownTroy (also referred to as NimDoor) to retrieve additional malicious scripts. Reporting also states CoreKitAgent monitors for user attempts to kill the malware process and helps ensure persistence. It is part of a multi-stage macOS malware ecosystem that includes AppleScript staging, persistence, command-and-control communications, and follow-on credential and data theft from browsers, Telegram, Keychain-related sources, and other applications. The activity has been attributed to DPRK-linked operators, with victims observed in Web3 and crypto-related organizations across multiple countries.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
DPRK

The researchers detail how NimDoor deploys two key binaries: a loader with the misspelled name GoogIe LLC (using an uppercase ‘i’ rather than lowercase ‘L’) and a trojan called CoreKitAgent.

via sentinelone blogsentinelone.com
Lazarus

DownTroy v2, which uses a dropper named CoreKitAgent to launch Nimcore loader, which then launches AppleScript-based DownTroy (aka NimDoor)...

via the hacker newsthehackernews.com
APT38

DownTroy v2, which uses a dropper named CoreKitAgent to launch Nimcore loader, which then launches AppleScript-based DownTroy (aka NimDoor)...

via the hacker newsthehackernews.com
North Korean threat actors

Also dropped as part of the attacks is a collection of Nim-based executable that are used as a launchpad for CoreKitAgent, which monitors for user attempts to kill the malware process and ensures persistence.

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

1 distinct technique documented for this family, organized by ATT&CK tactic.

Persistence

1 technique
T1546Event Triggered ExecutionEvidence1

"A novel persistence mechanism takes advantage of SIGINT/SIGTERM signal handlers to install persistence when the malware is terminated or the system rebooted."

T1546Event Triggered ExecutionEvidence1

"A novel persistence mechanism takes advantage of SIGINT/SIGTERM signal handlers to install persistence when the malware is terminated or the system rebooted."

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution4

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping1

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.