Brief Analysis on APT Attack through Cryptocurrency Trading Software
2018-08-15 • Qihoo360 •
360 Core Security attributed a cryptocurrency-sector attack, tracked as APT-C-26 and suspected to involve Lazarus, to trojanized digital currency trading software named Celas Trade Pro. The attackers modified the open source Qt Bitcoin Trader application by adding an updater backdoor and promoted the fake trading software to cryptocurrency institutions and related individuals. The Windows and macOS versions collected process lists, computer names, and system information, encrypted the data, sent it to a server, and executed malicious code returned by the server. The report identifies celasllc.com/checkupdate.php and sample hashes as key indicators, highlighting continued targeting of cryptocurrency users and organizations for financially motivated operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | aeee54a81032a6321a39566f96c822f5 | 2018-08-15 | 2020-01-08 |
| HASH | b054a7382adf6b774b15f52d971f3799 | 2018-08-15 | 2018-08-23 |
| URL | https://www.celasllc.com/checku… | 2018-08-15 | 2018-08-23 |