Lazarus ‘Operation In(ter)ception’ Targets macOS Users Dreaming of Jobs in Crypto
2022-09-26 • Sentinel One •
Lazarus continued Operation In(ter)ception against cryptocurrency-sector targets by shifting macOS job-lure decoys from Coinbase-themed vacancies to Crypto.com positions. The Crypto.com variant used a Mach-O first-stage dropper that created a WifiPreference directory, installed LaunchAgent persistence at ~/Library/LaunchAgents/com.wifianalyticsagent.plist, opened a decoy job PDF, and launched a staged application bundle. The second stage extracted and ran wifianalyticsagent, a downloader configured to contact market.contradecapital[.]com and write a later payload as WifiCloudWidget, although the C2 was offline during analysis. The campaign matters because it shows a long-running Lazarus pattern of using recruiting lures against cryptocurrency exchange personnel, extending earlier AppleJeus and Operation Dream Job tradecraft onto macOS systems.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | concrecapital.com | 2022-09-26 | 2023-10-04 |
| HASH | 65b7091af6279cf0e426a7b9bdc4591… | 2022-09-26 | 2022-09-26 |
| HASH | 1f0f9020f72aa5a38a89ffd6cd000ed… | 2022-09-26 | 2022-09-26 |
| HASH | a57684cc460d4fc202b8a3387063041… | 2022-09-26 | 2022-09-26 |
| HASH | 1b32f332e7fc91252181f0626da05ae… | 2022-09-26 | 2022-09-26 |
| DOMAIN | market.contradecapital.com | 2022-09-26 | 2022-09-26 |