We speculate that this is an intermediate stage in significant changes to their macOS malware. It doesn’t have an encryption/decryption routine for network communication. We recognized a different type of macOS malware, MarkMakingBot.dmg (be37637d8f6c1fbe7f3ffc702afdfe1d), created on. However, they have started changing their macOS malware. These three macOS installers use a similar post installer script in order to implant a mach-o payload, as well as using the same command-line argument when executing the fetched second-stage payload. The malware authors used QtBitcoinTrader developed by Centrabit. This macOS malware used public source code in order to build crafted macOS installers. We found more macOS malware similar to that used in the original Operation AppleJeus case. We assess that the Lazarus group has been more careful in its attacks following the release of Operation AppleJeus and they have employed a number of methods to avoid being detected.įor more information, please contact: Life after Operation AppleJeusĪfter releasing Operation AppleJeus, the Lazarus group continued to use a similar modus operandi in order to compromise cryptocurrency businesses. In addition, to attack Windows users, they have elaborated a multi-stage infection procedure, and significantly changed the final payload. To attack macOS users, the Lazarus group has developed homemade macOS malware, and added an authentication mechanism to deliver the next stage payload very carefully, as well as loading the next-stage payload without touching the disk. As a result of our ongoing efforts, we identified significant changes to the group’s attack methodology. Notably, this operation marked the first time Lazarus had targeted macOS users, with the group inventing a fake company in order to deliver their manipulated application and exploit the high level of trust among potential victims. In 2018, Kaspersky published a report on one of their campaigns, named Operation AppleJeus. The Lazarus group is currently one of the most active and prolific APT actors.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |