Lazarus ‘Operation In(ter)ception’ Targets macOS Users Dreaming of Jobs in Crypto

2022-09-26 Sentinel One

https://www.sentinelone.com/blog/lazarus-operation-interception-targets-macos-users-dreaming-of-jobs-in-crypto/

Thumbnail for Lazarus ‘Operation In(ter)ception’ Targets macOS Users Dreaming of Jobs in Crypto

Lazarus continued Operation In(ter)ception against cryptocurrency-sector targets by shifting macOS job-lure decoys from Coinbase-themed vacancies to Crypto.com positions. The Crypto.com variant used a Mach-O first-stage dropper that created a WifiPreference directory, installed LaunchAgent persistence at ~/Library/LaunchAgents/com.wifianalyticsagent.plist, opened a decoy job PDF, and launched a staged application bundle. The second stage extracted and ran wifianalyticsagent, a downloader configured to contact market.contradecapital[.]com and write a later payload as WifiCloudWidget, although the C2 was offline during analysis. The campaign matters because it shows a long-running Lazarus pattern of using recruiting lures against cryptocurrency exchange personnel, extending earlier AppleJeus and Operation Dream Job tradecraft onto macOS systems.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN concrecapital.com 2022-09-26 2023-10-04
HASH 65b7091af6279cf0e426a7b9bdc4591… 2022-09-26 2022-09-26
HASH 1f0f9020f72aa5a38a89ffd6cd000ed… 2022-09-26 2022-09-26
HASH a57684cc460d4fc202b8a3387063041… 2022-09-26 2022-09-26
HASH 1b32f332e7fc91252181f0626da05ae… 2022-09-26 2022-09-26
DOMAIN market.contradecapital.com 2022-09-26 2022-09-26

Related Reports

« Back