Lazarus Group Goes 'Fileless'
2019-12-03 • Objective-see •
Objective-See analyzed a Lazarus-linked macOS implant delivered through a trojanized UnionCryptoTrader application, continuing the group’s pattern of targeting cryptocurrency exchange users and administrators with fake trading software. The infection chain used a malicious DMG and package installer that prompted for credentials, moved a LaunchDaemon plist into /Library/LaunchDaemons, installed unioncryptoupdater under /Library/UnionCrypto, and launched it with root privileges. The sample was associated with unioncrypto.vip, which resolved to 104.168.167.16 and hosted a download path for the malicious application. The report highlights increasingly capable Lazarus macOS tradecraft, including persistent installation and remote download or in-memory execution behavior, which matters for defenders monitoring cryptocurrency-sector endpoints.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 55554944ee2cb96a1f5132ce8788c3f… | 2019-12-03 | 2023-04-01 |
| DOMAIN | unioncrypto.vip | 2019-12-03 | 2021-02-17 |
| URL | https://www.unioncrypto.vip/dow… | 2019-12-03 | 2021-02-17 |
| IPv4 | 104.168.167.16 | 2019-12-03 | 2021-02-17 |
| HASH | 6588d262529dc372c400bef8478c2eec | 2019-12-03 | 2020-02-22 |
| URL | https://unioncrypto.vip/update | 2019-12-03 | 2020-02-22 |
| URL | https://unioncrypto.vip/ | 2019-12-03 | 2020-02-22 |
| HASH | 8d204e5b7ae08e80b728de675aeb8cc… | 2019-12-03 | 2020-01-01 |