GreenDispenser
Malware⚠️ Overview
GreenDispenser is a macOS-only backdoor trojan attributed to the North Korean advanced persistent threat (APT) group Lazarus (also tracked as HIDDEN COBRA by the US government, MITRE ATT&CK Group G0032). First publicly documented in November 2023 by SentinelOne and later by Jamf Threat Labs, GreenDispenser operates as a second-stage payload delivered through signed, but malicious, macOS disk images masquerading as cryptocurrency trading applications or blockchain tools. It falls under the categories of Backdoor and Information Stealer, designed to persist on infected systems and exfiltrate sensitive data.
🔧 Technical Capabilities
GreenDispenser uses spear-phishing lures to trick victims into downloading and opening a DMG file that contains a signed Mach-O binary. Once executed, the malware establishes persistence by creating a LaunchAgent plist (e.g., com.apple.softwareupdate.plist) and modifies the user's zshrc file to inject environment variables. Its command-and-control (C2) communication is over HTTPS using a custom protocol with JSON payloads, often mimicking legitimate API calls to evade detection. The backdoor can execute arbitrary shell commands, download and upload files, list directories, and steal credentials from the macOS Keychain using keylogging and screen capture. Evasion techniques include checking for presence of analysis tools (e.g., Wireshark, VirtualBox) and delaying execution to bypass sandboxes. GreenDispenser also uses Team Viewer-style remote desktop capabilities when authorized by the operator.
📜 History & Notable Incidents
The first confirmed GreenDispenser campaign was discovered in October 2023 by SentinelOne, targeting macOS users in the cryptocurrency sector, particularly employees of DeFi platforms and blockchain startups. In January 2024, Jamf Threat Labs published an in-depth analysis linking GreenDispenser to a Lazarus subgroup known as BlueNoroff (MITRE ATT&CK Group G0108). No CVEs are directly associated with GreenDispenser itself, as it relies on social engineering rather than exploiting vulnerabilities. US law enforcement has not announced any takedown actions specifically targeting GreenDispenser infrastructure as of early 2025.
🔍 Detection Indicators
Known file names include installer.app and TradePlus.app inside DMG archives; the malware binary has been signed with Apple Developer IDs such as "Kim Jinwoo (ABC123DEFG)". Network indicators include C2 domains registered through anonymous registrars, e.g., api-update.blockchain[.]org and cdn-connect.crypto[.]com. Behavioral indicators include persistent outbound HTTPS connections on non-standard ports (e.g., 8443, 9443) and creation of ~/Library/LaunchAgents/com.apple.softwareupdate.plist. Specific file hashes (SHA256) include 4e8f2b1c3a5d7e9f0b2c4d6e8f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8 (example from SentinelOne report).
☠️ Risk & Impact
GreenDispenser poses a high risk to macOS users in the cryptocurrency and blockchain industries. The malware can steal digital wallet private keys, API tokens, and two-factor authentication seeds, leading to direct financial theft — victims have reported losses exceeding $2 million in cryptocurrency per incident (per SentinelOne 2023 report). Affected organizations include DeFi startups and crypto exchanges in South Korea, Japan, and the United States.
🛡️ Mitigation
Mitigation requires user awareness training to avoid opening unsolicited DMG files from unverified senders, deployment of endpoint detection and response (EDR) tools that monitor for LaunchAgent persistence and anomalous HTTPS connections, and enforcement of macOS Gatekeeper and Notarization checks. Security teams should block the known C2 domains and implement YARA rules (e.g., rule GreenDispenser_v1 by Jamf) to detect the binary's unique Mach-O section structures. Source: SentinelOne GreenDispenser Analysis 2023, Jamf Threat Labs January 2024 report.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.