Lazarus group uses fake cryptocurrency apps to plant AppleJeus malware
2022-12-05 • Malwarebytes •
Malwarebytes summarized Volexity’s reporting on a Lazarus Group AppleJeus campaign targeting cryptocurrency users and organizations. The activity used the fake BloxHolder cryptocurrency application and a cloned HaasOnline-themed website at bloxholder[.]com to distribute a Windows MSI installer bundled with QTBitcoinTrader. The installer created a scheduled task to run CameraSettingsUIHost.exe and abused DLL side-loading through dui70.dll and malicious DUser.dll. The campaign fits Lazarus’s long-running use of trojanized cryptocurrency applications to gain access, deploy additional malware, and enable cryptocurrency theft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | rebelthumb.net | 2022-12-01 | 2024-09-18 |
| DOMAIN | strainservice.com | 2022-12-01 | 2023-10-26 |
| DOMAIN | wirexpro.com | 2022-12-01 | 2023-04-03 |
| DOMAIN | oilycargo.com | 2022-12-01 | 2023-04-03 |
| HASH | 18e190413af045db88dfbd29609eb877 | 2022-12-01 | 2022-12-05 |
| DOMAIN | telloo.io | 2022-12-01 | 2022-12-05 |
| DOMAIN | bloxholder.com | 2022-12-01 | 2022-12-05 |
Related Actors
Related Reports
Shares tags: Cryptocurrency, AppleJeus • Shares 7 IOCs • Published within a week
Shares tags: Cryptocurrency, AppleJeus • Shares 1 IOC • Published within a week
2023-01-23 •
56% Match
FBI Confirms Lazarus Group, APT38 Cyber Actors Responsible for Harmony's Horizon Bridge Currency Theft
USFBI
Shares tags: APT38, Cryptocurrency
2026-05-29 •
46% Match
#Cryptocurrency
#AppleJeus
#Fileless
#Finance
#UNC4736
#FinancialGain
#Espionage
#CitrineSleet
#Lazarus
#GleamingPisces
#POOLRAT
#PondRAT
#RemotePE
#ThemeForestRAT
#T1071.001
#T1027
#T1055
#T1562.006
Shares tags: Cryptocurrency, AppleJeus
Shares tags: APT38, Cryptocurrency
Shares tags: APT38, Cryptocurrency