• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
north korean hackers spread applejeus malware disguised as cryptocurrency apps

North Korean Hackers Spread AppleJeus Malware Disguised as Cryptocurrency Apps

You are here: Home / General Cyber Security News / North Korean Hackers Spread AppleJeus Malware Disguised as Cryptocurrency Apps
December 5, 2022

The Lazarus Group threat actor has been observed leveraging pretend cryptocurrency apps as a entice to provide a formerly undocumented model of the AppleJeus malware, in accordance to new results from Volexity.

“This action notably involves a marketing campaign probable concentrating on cryptocurrency people and businesses with a variant of the AppleJeus malware by way of destructive Microsoft Office environment paperwork,” researchers Callum Roxan, Paul Rascagneres, and Robert Jan Mora mentioned.

The North Korean authorities is identified to adopt a 3-pronged technique by utilizing destructive cyber activity developed to gather intelligence, conduct attacks, and create illicit income for the sanctions strike nation. The threats are collectively tracked beneath the identify Lazarus Group (aka Concealed Cobra or Zinc).

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


CyberSecurity

“North Korea has done cyber theft from money establishments and cryptocurrency exchanges worldwide, potentially stealing hundreds of tens of millions of pounds, almost certainly to fund government priorities, such as its nuclear and missile plans,” per the 2021 Yearly Danger Evaluation introduced by U.S. intelligence organizations.

Earlier this April, the Cybersecurity and Infrastructure Security Company (CISA) warned of an exercise cluster dubbed TraderTraitor that targets cryptocurrency exchanges and trading companies as a result of trojanized crypto apps for Windows and macOS.

AppleJeus Malware

Whilst the TraderTraitor attacks culminate in the deployment of the Manuscrypt distant access trojan, the new action helps make use of a meant crypto investing site named BloxHolder, a copycat of the respectable HaasOnline system, to provide AppleJeus through an installer file.

AppleJeus, 1st documented by Kaspersky in 2018, is intended to harvest information about the contaminated system (i.e., MAC tackle, laptop or computer title, and working method version) and obtain shellcode from a command-and-control (C2) server.

The attack chain is claimed to have undergone a slight deviation in Oct 2022, with the adversary shifting from MSI installer documents to a booby-trapped Microsoft Excel doc that takes advantage of macros to down load a remotely hosted payload, a PNG graphic, from OpenDrive.

The plan behind the change is probably to lessen static detection by security items, Volexy stated, introducing it could not attain the impression file (“Qualifications.png”) from the OpenDrive website link but pointed out it embeds a few information, which includes an encoded payload that’s subsequently extracted and introduced on the compromised host.

“The Lazarus Team proceeds its energy to concentrate on cryptocurrency users, even with ongoing interest to their strategies and strategies,” the scientists concluded.

Identified this article intriguing? Comply with us on Twitter  and LinkedIn to study a lot more exceptional material we write-up.


Some sections of this report are sourced from:
thehackernews.com

Previous Post: «Cyber Security News Microsoft: Beware Russian Winter Cyber-Offensive
Next Post: Digital Giant ABB to Pay $315m in Bribery Case Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • WhatsApp Unveils Proxy Support to Tackle Internet Censorship
  • Hackers Using CAPTCHA Bypass Tactics in Freejacking Campaign on GitHub
  • Blind Eagle Hacking Group Targets South America With New Tools
  • US Family Planning Non-Profit MFHS Confirms Ransomware Attack
  • Microsoft Reveals Tactics Used by 4 Ransomware Families Targeting macOS
  • Dridex Malware Now Attacking macOS Systems with Novel Infection Method
  • Cyber attacks on UK organisations surged 77% in 2022, new research finds
  • WhatsApp to combat internet blackouts with proxy server support
  • The IT Pro Podcast: Going passwordless
  • Podcast transcript: Going passwordless

Copyright © TheCyberSecurity.News, All Rights Reserved.