In this talk, a continuation of the North Korea's Zoo series, we take apart three new malware samples linked to North Korean operators: a fresh iteration of GoLangGhostRAT, POWerful Armadillo (a rework of Digit Stealer), and Mach-O Man, a new macOS malware kit. All of them were first-spotted and reversed by our team.
We will focus on what actually matters: interesting bits of code, mistakes in their infrastructure, and how we were able to abuse their C2 to profile campaigns and mess with their operations.
We'll also cover how these samples are being distributed, including some newer tricks we've been seeing in the wild.
At several points, we ended up talking directly with the operators themselves. We'll be sharing those interactions here for the first time.
This talk can be enjoyed by both beginners and seasoned threat hunters alike.
Presented at Malware Village — DEF CON 2026