Lazarus group uses fake cryptocurrency apps to plant AppleJeus malware

2022-12-05 Malwarebytes

https://www.malwarebytes.com/blog/news/2022/12/lazarus-group-uses-fake-cryptocurrency-apps-to-plant-applejeus-malware

Thumbnail for Lazarus group uses fake cryptocurrency apps to plant AppleJeus malware

Malwarebytes summarized Volexity’s reporting on a Lazarus Group AppleJeus campaign targeting cryptocurrency users and organizations. The activity used the fake BloxHolder cryptocurrency application and a cloned HaasOnline-themed website at bloxholder[.]com to distribute a Windows MSI installer bundled with QTBitcoinTrader. The installer created a scheduled task to run CameraSettingsUIHost.exe and abused DLL side-loading through dui70.dll and malicious DUser.dll. The campaign fits Lazarus’s long-running use of trojanized cryptocurrency applications to gain access, deploy additional malware, and enable cryptocurrency theft.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN rebelthumb.net 2022-12-01 2024-09-18
DOMAIN strainservice.com 2022-12-01 2023-10-26
DOMAIN wirexpro.com 2022-12-01 2023-04-03
DOMAIN oilycargo.com 2022-12-01 2023-04-03
HASH 18e190413af045db88dfbd29609eb877 2022-12-01 2022-12-05
DOMAIN telloo.io 2022-12-01 2022-12-05
DOMAIN bloxholder.com 2022-12-01 2022-12-05

Related Actors

Related Reports

« Back