• Latest
  • Trending
Lazarus APT uses fake cryptocurrency apps to spread AppleJeus MalwareSecurity Affairs

Lazarus APT uses fake cryptocurrency apps to spread AppleJeus MalwareSecurity Affairs

December 5, 2022
Ethereum staking withdrawal testnet Zhejiang to go online Feb. 1

Ethereum staking withdrawal testnet Zhejiang to go online Feb. 1

February 1, 2023
My Big Coin cryptocurrency firm founder gets 8 years in prison for fraud

My Big Coin cryptocurrency firm founder gets 8 years in prison for fraud

February 1, 2023
Long list of celebrity endorsers named in crypto/NFT lawsuits

Long list of celebrity endorsers named in crypto/NFT lawsuits

February 1, 2023
Cryptocurrency Price Today In India January 26 Check Global Market Cap Bitcoin BTC Ethereum Doge Solana Litecoin Threshold Gainer Loser

Cryptocurrency Price Today: Bitcoin, Ethereum See Gains Ahead Of Union Budget

February 1, 2023
Bitcoin poised for another attack on $24K as trader predicts ‘bearish February’

Bitcoin poised for another attack on $24K as trader predicts ‘bearish February’

February 1, 2023
Warrant Buffet backs RippleNet’s Nubank while SEC vs Ripple case drags on

Ripple primed for weakness on diverging momentum

February 1, 2023
Crypto Price Today: Bitcoin regains $23,000; Cardano rallies 4%, Solana drops

Crypto Price Today: Bitcoin regains $23,000; Cardano rallies 4%, Solana drops

February 1, 2023
Altcoin Prices Are Surging | InvestorPlace

Altcoin Prices Are Surging | InvestorPlace

February 1, 2023
Bitcoin on-chain data and BTC’s recent price rally point to a healthier ecosystem

Bitcoin on-chain data and BTC’s recent price rally point to a healthier ecosystem

February 1, 2023
Blockchain provider SIMBA Chain awarded $30M by US Air Force STRATFI program

Blockchain provider SIMBA Chain awarded $30M by US Air Force STRATFI program

February 1, 2023
Peterson: Mississippi Should Embrace Bitcoin Mining

Peterson: Mississippi Should Embrace Bitcoin Mining

February 1, 2023
Mooners and Shakers: DOGE, dYdX and IMX surge; Finder panel predicts $14k ETH by 2030

Mooners and Shakers: DOGE, dYdX and IMX surge; Finder panel predicts $14k ETH by 2030

February 1, 2023
Harvest Protocol News
Wednesday, February 1, 2023
  • Home
  • ADA
  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Crypto Mining
  • Altcoins
  • Dogecoin
  • Ethereum
  • ICO
  • Litecoin
  • Market & Analysis
  • Ripple
  • Ledger
Harvest Protocol News
No Result
View All Result

Lazarus APT uses fake cryptocurrency apps to spread AppleJeus MalwareSecurity Affairs

by truestfreedom
December 5, 2022
in Cryptocurrency
0


The North Korea-linked Lazarus APT spreads pretend cryptocurrency apps below the pretend model BloxHolder to put in the AppleJeus malware.

Volexity researchers warn of a brand new malware marketing campaign carried out by the North Korea-linked Lazarus APT towards cryptocurrency customers. The menace actors have been noticed spreading pretend cryptocurrency apps below the pretend model BloxHolder to ship the AppleJeus malware for preliminary entry to networks and steal crypto property.

The APT group employed the AppleJeus malware since no less than 2018 to steal cryptocurrencies from the victims.

The brand new marketing campaign noticed by Volexity began in June 2022, the APT group registered the area title bloxholder[.]com, after which arrange an internet site associated to automated cryptocurrency buying and selling.

The brand new marketing campaign attributed to Lazarus began in June 2022 and was lively till no less than October 2022.

On this marketing campaign, the menace actors used the “bloxholder[.]com” area, a clone of the HaasOnline automated cryptocurrency buying and selling platform.

The web site is a clone of the authentic web site, HaasOnline (haasonline[.]com.)

Volexity_AppleJeus Lazarus Figure-01-2048x899

The attackers used the web site to distribute a Home windows MSI installer masquerading because the BloxHolder app, which was used to put in AppleJeus malware together with the QTBitcoinTrader app.

“This found file, the  “BloxHolder software”, is definitely one other case of AppleJeus being put in alongside the open-source cryptocurrency buying and selling software QTBitcoinTrader that’s available on GitHub. This identical authentic software has beforehand been utilized by the Lazarus Group, as documented in this report from CISA.” reads the report revealed by Volexity. “The MSI file is used to put in each the malicious and legit functions on the identical time.”

In October 2022, the researchers noticed the Lazarus Group putting in AppleJeus utilizing a weaponized Microsoft Workplace doc, named ‘OKX Binance & Huobi VIP payment comparision.xls,’ as an alternative of an MSI installer.

The doc incorporates a macro cut up into two elements, the primary one is used to decode a base64 blob that incorporates a second OLE object containing a second macro. The preliminary doc additionally shops a number of variables, encoded utilizing base64, that permit defining the place the malware will likely be deployed within the contaminated system.

The final stage payload is downloaded from a public file-sharing service, OpenDrive. 

Volexity specialists weren’t capable of retrieve the ultimate payload employed since October, however they seen similarities within the DLL sideloading mechanism which is analogous to the one used within the assaults counting on MSI installer.

“Whereas the file was not accessible on the time of study, primarily based on public sandbox outcomes for the file in query, the downloaded payload, “Background.png”, embeds the next three recordsdata:

  • “Logagent.exe” – a authentic file (md5: eb1e19613a6a260ddd0ae9224178355b)
  • “wsock32.dll” – a side-loaded library internally named HijackingLib.dll (md5: e66bc1e91f1a214d098cf44ddb1ae91a)
  • “56762eb9-411c-4842-9530-9922c46ba2da” – an encoded payload decoded by “wsock32.dll”

“continues the evaluation. “The three recordsdata are dropped on disk utilizing hardcoded offsets that may be discovered within the second macro.”

Specialists speculate Lazarus used DLL sideloading to keep away from malware evaluation, the menace actors additionally seen that latest AppleJeus samples obfuscated strings and API calls utilizing a customized algorithm.

“The Lazarus Group continues its effort to focus on cryptocurrency customers, regardless of ongoing consideration to their campaigns and techniques. Maybe in an try to allude detection, they’ve determined to make use of chained DLL side-loading to load their payload. Moreover, Volexity has not beforehand famous the usage of Microsoft Workplace paperwork to deploy AppleJeus variants.” concludes volexity. “Regardless of these modifications, their targets stay the identical, with the cryptocurrency business being a spotlight as a method for the DPRK to bolster their funds.”

Comply with me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, APT)

YOU MAY ALSO LIKE

My Big Coin cryptocurrency firm founder gets 8 years in prison for fraud

U.S. Promoter of Foreign Cryptocurrency Companies Sentenced to 60 Months in Prison for His Role in Multi-Million Dollar Securities Fraud Scheme | USAO-EDNY



Share On






Source link

Tags: AffairsAppleJeusAppsAPTCryptocurrencyFakeLazarusMalwareSecurityspread
ShareTweetShare

Search

No Result
View All Result

Recent News

Ethereum staking withdrawal testnet Zhejiang to go online Feb. 1

Ethereum staking withdrawal testnet Zhejiang to go online Feb. 1

February 1, 2023
My Big Coin cryptocurrency firm founder gets 8 years in prison for fraud

My Big Coin cryptocurrency firm founder gets 8 years in prison for fraud

February 1, 2023
Long list of celebrity endorsers named in crypto/NFT lawsuits

Long list of celebrity endorsers named in crypto/NFT lawsuits

February 1, 2023

About us

Harvest Protocol is the people’s bitcoin mining company that also happens to deliver you the latest crypto news.

Tiktok

Recent News

Ethereum staking withdrawal testnet Zhejiang to go online Feb. 1

My Big Coin cryptocurrency firm founder gets 8 years in prison for fraud

Long list of celebrity endorsers named in crypto/NFT lawsuits

© 2023 Harvest Protocol

  • About Us
  • Contact Us
  • Privacy & policy
  • About Us
  • Contact Us
  • Privacy & policy
No Result
View All Result
  • Home
  • ADA
  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Crypto Mining
  • Altcoins
  • Dogecoin
  • Ethereum
  • ICO
  • Litecoin
  • Market & Analysis
  • Ripple
  • Ledger

© 2022 news.harvestprotocol.com