Brief Analysis on APT Attack through Cryptocurrency Trading Software

2018-08-15 Qihoo360

http://blogs.360.cn/blog/apt-c-26/

360 Core Security attributed a cryptocurrency-sector attack, tracked as APT-C-26 and suspected to involve Lazarus, to trojanized digital currency trading software named Celas Trade Pro. The attackers modified the open source Qt Bitcoin Trader application by adding an updater backdoor and promoted the fake trading software to cryptocurrency institutions and related individuals. The Windows and macOS versions collected process lists, computer names, and system information, encrypted the data, sent it to a server, and executed malicious code returned by the server. The report identifies celasllc.com/checkupdate.php and sample hashes as key indicators, highlighting continued targeting of cryptocurrency users and organizations for financially motivated operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH aeee54a81032a6321a39566f96c822f5 2018-08-15 2020-01-08
HASH b054a7382adf6b774b15f52d971f3799 2018-08-15 2018-08-23
URL https://www.celasllc.com/checku… 2018-08-15 2018-08-23

Related Actors

Related Reports

« Back