Lazarus Hacking Group Targets Crypto Exchanges with MacOS Malware, Kaspersky Warns

von Satoshi Nakamoto

Lazarus Hacking Group Targets Crypto Exchanges with MacOS Malware, Kaspersky Warns

The North Korean hackers are deploying new elaborated malware, targeting Apple’s MacOS platform.




articleStartImage

Lazarus, a notorious hacking group allegedly operating from North Korea, is now deploying new MacOS-based malware to infiltrate cryptocurrency exchanges, Russian anti-virus and cybersecurity provider Kaspersky Labs has warned.


Lazarus is believed to be responsible for major online attacks, including last year’s $80 million Bangladesh Central Bank cyber heist and 2014’s Sony Pictures hack. The cybercriminals are also thought to be behind the recent attacks on South Korean cryptocurrency exchanges Bithumb, Youbit and Coinlink.


According to a Kaspersky report published last week, over the last few months Lazarus has “successfully compromised several banks and infiltrated a number of global cryptocurrency exchanges and fintech companies”. In addition to the already popular Windows malware, the researchers have identified a new version of Lazarus’ virus, targeting Apple’s MacOS platform.



“To ensure that the OS platform was not an obstacle to infecting targets, it seems the attackers went the extra mile and developed malware for other platforms, including for macOS. A version for Linux is apparently coming soon,” Kaspersky warned.



The new malware campaign called AppleJeus was first spotted after it had successfully compromised an unnamed Asian cryptocurrency exchange. Vitaly Kamluk from Kaspersky Lab told Bleeping Computer that the victim did not suffered any financial losses as the threat was contained based on the cybersecurity firm’s notification.


In a detailed announcement, Kaspersky explained the hack took place after one of the exchange's employees downloaded an app from a “legitimate-looking” website that claimed to be from a company that develops cryptocurrency trading software. The victim’s system was then infected with Fallchill, a remote access trojan (RAT) known to be associated with the Lazarus Group since at least 2016.


The researchers further noted that AppleJeus is not embedded in the code frame of the infected application. Instead, the virus looks for cryptocurrency info on the system to check if it is worth compromising and then uses a hidden updated component to control infrastructure and initiate the process of stealing the cryptocurrency via a second-stage installation. This allowed the malicious code to go under the radar during the initial download process.


Hackers have traditionally been targeting only Windows-based computers, leading to the common belief that MacOS and Linux operating systems are more secure. Kaspersky’s recent research concluded that its latest findings “should be a wake-up call for users of non-Windows platforms”.


Last month, Kaspersky issued a report analyzing the main patterns and trends related to cryptocurrency hacks. The cybersecurity provider revealed that it had prevented over 100,000 crypto theft attempts since the beginning of 2018.





Source link

Read the full article
Porträt von Satoshi Nakamoto

Satoshi Nakamoto

Zur Person

Satoshi Nakamoto