Lazarus Group Evolves Fileless Mac Threat

2019-12-06 K7Security Labs

https://labs.k7computing.com/index.php/lazarus-group-evolves-fileless-mac-threat/

K7 Computing describes a Lazarus-attributed macOS campaign using a Trojanized UnionCryptoTrader cryptocurrency trading application distributed from unioncrypto.vip. The installer abused a post-install shell script to move a LaunchDaemon plist and loader into system locations, establishing persistence and executing the UnionCrypto updater component. The loader collected the Mac serial number and OS information, posted them to Lazarus command-and-control infrastructure, and could decrypt a returned payload using base64 decoding and AES decryption. Static analysis showed the payload could be executed directly from memory via Mach-O loading APIs or written to disk with executable permissions, highlighting Lazarus experimentation with fileless macOS delivery.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 2ab58b7ce583402bf4cbc90bee643ba… 2019-12-06 2021-02-18

Related Actors

Related Reports

« Back