KandyKorn is a macOS backdoor that Elastic Security Labs documented in November 2023 as the final payload in a targeted, five-stage intrusion. The reported victims were blockchain engineers at a cryptocurrency exchange, lured through Discord with a Python application presented as a cryptocurrency arbitrage bot. Infection required a person to download and run the supplied code; the reporting does not describe an automatic infection or a vulnerability affecting Mac users generally.
What is KandyKorn malware?
KANDYKORN (also written KandyKorn) is the final-stage malware in an intrusion Elastic Security Labs tracked as REF7001. Elastic attributed the activity to the Democratic People’s Republic of Korea (DPRK) and reported overlaps with Lazarus Group based on observed techniques, infrastructure, certificates, and detection rules. Those are Elastic’s assessments; the reporting does not independently prove that Lazarus conducted every attack involving KandyKorn.
The payload gave an operator capabilities associated with remote access and data theft. Elastic documented functions for collecting system information, finding and examining files, transferring files, compressing and exfiltrating directories, killing processes, and running commands or an interactive shell. These are capabilities of the malware, not proof that every function was used against every victim.
Who was targeted, and how did the attack start?
Elastic’s account describes blockchain engineers at a cryptocurrency exchange platform as the targets. An attacker contacted a potential victim by direct message on a public Discord server and shared an archive called Cross-Platform Bridges.zip. It contained a Python application posing as cryptocurrency arbitrage software.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors#1 Best Overall
The victim downloaded the archive and manually opened Main.py in PyCharm. That script imported Watcher.py, beginning the infection chain. Elastic observed social engineering and user-run code—not a report that simply visiting a website or using Discord’s service automatically infected a Mac. As Elastic Security Labs put it: “The intrusion required interactivity from the victim that would still be expected had the lure been legitimate.”
How did the five-stage KandyKorn chain work?
Elastic labels the chain from stage 0 through stage 4. The table summarizes the role of each stage in its reported intrusion; it is not a claim that every deployment must follow the same sequence.
Rank #2
| Stage | Component | Role in the reported chain |
|---|---|---|
| 0 | Watcher.py |
Initial compromise: imported by the victim-run Main.py script and used to fetch and execute additional Python code. |
| 1 | testSpeed.py and FinderTools |
Droppers that advanced the infection; FinderTools downloaded the next payload. |
| 2 | SUGARLOADER | An obfuscated Mach-O payload that retrieved configuration and loaded later code, including KANDYKORN. |
| 3 | HLOADER | A fake Discord loader that altered the local Discord application bundle to establish persistence. |
| 4 | KANDYKORN | The final payload, with system-discovery, file-handling, exfiltration, process-control, and command-execution capabilities. |
Stages 0 and 1: Python scripts and droppers
After the victim ran the archive’s Python application, Watcher.py fetched and executed further Python code, including testSpeed.py and FinderTools. FinderTools then downloaded SUGARLOADER. The initial program depended on the victim’s decision to run it, which is why an unsolicited “trading tool” or coding project from a stranger deserves scrutiny even when it appears relevant to someone’s work.
Stage 2: SUGARLOADER retrieves and loads the payload
SUGARLOADER checked for a configuration file at /Library/Caches/com.apple.safari.ck. If the file was absent, it fetched it from command-and-control infrastructure and used the configuration to obtain later stages. Elastic reported that SUGARLOADER reflectively loaded KANDYKORN into memory, reducing the final payload’s reliance on a conventional executable saved to disk.
Stage 3: HLOADER tampers with the local Discord app
HLOADER replaced the Discord executable inside the application bundle and renamed the legitimate executable. It then restored and launched the genuine application alongside the loader. Elastic and SentinelOne described this as a persistence technique that exploited the likelihood the victim would open Discord again. The reported activity involved changes to files on the victim’s Mac; it does not mean Discord’s service itself was compromised or malicious.
Stage 4: KANDYKORN enables operator actions
Once loaded, KANDYKORN could support actions including system reconnaissance, file discovery and transfer, directory compression and exfiltration, process termination, and command or shell execution. The significance is the range of access those functions could give an operator—not evidence that all listed actions occurred in every case.
Rank #4
Does KandyKorn target all Mac users?
No such broad conclusion is supported by the reports described here. Elastic’s November 2023 account concerns a targeted operation against blockchain engineers at a cryptocurrency exchange, using a specific social-engineering lure and a victim-run Python program. The available reporting does not establish a victim count, campaign-wide prevalence, or that ordinary Mac users were broadly targeted by this operation.
The word “new” in the original headline refers to reporting at the time. Elastic published its detailed account on November 1, 2023, and SentinelOne published a follow-up on November 28, 2023. Palo Alto Networks Unit 42 also discussed KandyKorn in a 2024 threat assessment. These historical reports do not, by themselves, establish whether the campaign or any listed infrastructure remains active today.
What did later reporting say about RustBucket and SwiftLoader?
SentinelOne’s November 28, 2023 follow-up reported later evidence connecting RustBucket/SwiftLoader droppers with KandyKorn payloads. SentinelOne’s interpretation was that components were likely being shared or mixed. That is a qualified assessment, distinct from Elastic’s original five-stage REF7001 chain; related tools or shared infrastructure alone do not prove that every associated campaign was the same operation.
What should Mac users and security teams watch for?
For individual users
- Be cautious with unsolicited archives or Python projects presented as cryptocurrency trading tools, arbitrage bots, or coding challenges—especially when a stranger asks you to run code locally.
- Do not treat a plausible name, professional context, or familiar-looking application as proof that a script is safe. Verify the sender and the project through a separate, trusted channel before running it.
- If you already ran an unexpected script, stop using the affected Mac for sensitive work and contact your organization’s security team if the device is managed or contains work credentials or data.
For defenders investigating a possible incident
- Review the origin and execution history of unfamiliar Python scripts, archives, and downloads, including activity in shared or temporary locations.
- Inspect unexpected changes inside
/Applications/Discord.app/Contents/MacOS/, and investigate references to/Library/Caches/com.apple.safari.ckin the context of the host’s timeline. - Correlate suspicious process activity with unexplained outbound connections and evidence of in-memory loading. A single path, filename, domain, or hash is not a complete detection rule.
- Use endpoint detection and response with verified macOS coverage, behavioral monitoring, investigation and response capabilities, and fleet-management features that fit the organization’s threat model. The cited reports do not establish that any specific commercial product will stop this campaign.
Elastic publishes detection and hunting material, but notes that findings from its queries require investigation and validation. SentinelOne also lists historical hashes, paths, and network indicators. Those indicators may help analysts review historical telemetry; the reporting does not establish that each remains active. Check current threat-intelligence sources and corroborate against local evidence before blocking an indicator or using it as an operational rule.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

