Lazarus Group Goes 'Fileless'

2019-12-03 Objective-see

https://objective-see.com/blog/blog_0x51.html

Thumbnail for Lazarus Group Goes 'Fileless'

Objective-See analyzed a Lazarus-linked macOS implant delivered through a trojanized UnionCryptoTrader application, continuing the group’s pattern of targeting cryptocurrency exchange users and administrators with fake trading software. The infection chain used a malicious DMG and package installer that prompted for credentials, moved a LaunchDaemon plist into /Library/LaunchDaemons, installed unioncryptoupdater under /Library/UnionCrypto, and launched it with root privileges. The sample was associated with unioncrypto.vip, which resolved to 104.168.167.16 and hosted a download path for the malicious application. The report highlights increasingly capable Lazarus macOS tradecraft, including persistent installation and remote download or in-memory execution behavior, which matters for defenders monitoring cryptocurrency-sector endpoints.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 55554944ee2cb96a1f5132ce8788c3f… 2019-12-03 2023-04-01
DOMAIN unioncrypto.vip 2019-12-03 2021-02-17
URL https://www.unioncrypto.vip/dow… 2019-12-03 2021-02-17
IPv4 104.168.167.16 2019-12-03 2021-02-17
HASH 6588d262529dc372c400bef8478c2eec 2019-12-03 2020-02-22
URL https://unioncrypto.vip/update 2019-12-03 2020-02-22
URL https://unioncrypto.vip/ 2019-12-03 2020-02-22
HASH 8d204e5b7ae08e80b728de675aeb8cc… 2019-12-03 2020-01-01

Related Actors

Related Reports

« Back