Mac cryptocurrency trading application rebranded, bundled with malware

2020-07-16 ESET

https://www.welivesecurity.com/2020/07/16/mac-cryptocurrency-trading-application-rebranded-bundled-malware/

Thumbnail for Mac cryptocurrency trading application rebranded, bundled with malware

ESET found malicious macOS cryptocurrency trading applications that copied or rebranded the legitimate Kattana app under names such as Licatrade and Cointrazer, continuing GMERA-style activity previously reported by Trend Micro. The trojanized bundles targeted cryptocurrency users by distributing fake trading apps from copycat websites, stealing browser cookies, cryptocurrency wallets, and screenshots while opening unencrypted reverse shells to attacker-controlled servers. The Licatrade sample reported victim details over HTTP to stepbystepby[.]com and attempted reverse-shell connections to 193.37.212[.]97 on ports including 25733 and 25734, with persistence attempted through a Launch Agent. Honeypot observations showed operators manually inspecting compromised Macs, collecting username, macOS version, location, hardware, display, and nearby Wi-Fi details before deciding whether the host was useful.

Indicators of Compromise

Type Value First Seen Last Seen
HASH e5d2c7fb4a64eaf444728e5c61f576f… 2020-07-16 2020-07-16
HASH da1fda04d4149ebf93756bcef758eb8… 2020-07-16 2020-07-16
HASH 4c688493958cc7cccfcb246e706184d… 2020-07-16 2020-07-16
HASH 9c0d839d1f3da0577a123531e5b4503… 2020-07-16 2020-07-16
HASH 1bc8ea284f9ce5f5f68c68531a410bc… 2020-07-16 2020-07-16
HASH af65b1a945b517c4d8baaa706aa1923… 2020-07-16 2020-07-16
HASH f6cd98a16e8cc2dd3ca1592d9911489… 2020-07-16 2020-07-16
HASH b8f19b02f9218a8dd803da1f8650195… 2020-07-16 2020-07-16
HASH 560071ef47fe5417fff62cb5c0e33b0… 2020-07-16 2020-07-16
HASH 575a43504f79297cbfa900b55c12dc8… 2020-07-16 2020-07-16
HASH 2ac42d9a11b67e8af7b610aa59aadcf… 2020-07-16 2020-07-16
HASH bdbd92bff8e349452b07e5f1d288367… 2020-07-16 2020-07-16
EMAIL [email protected] 2020-07-16 2020-07-16
DOMAIN trezarus.com 2020-07-16 2020-07-16
DOMAIN cupatrade.com 2020-07-16 2020-07-16
DOMAIN licatrade.com 2020-07-16 2020-07-16
DOMAIN nagsrsdfsudinasa.com 2020-07-16 2020-07-16
DOMAIN maccatreck.com 2020-07-16 2020-07-16
DOMAIN latinumtrade.com 2020-07-16 2020-07-16
DOMAIN narudina.com 2020-07-16 2020-07-16
DOMAIN stepbystepby.com 2020-07-16 2020-07-16
DOMAIN cointrazer.com 2020-07-16 2020-07-16
DOMAIN creditfinelor.com 2020-07-16 2020-07-16
DOMAIN apperdenta.com 2020-07-16 2020-07-16
DOMAIN trezarus.net 2020-07-16 2020-07-16
DOMAIN macstockfolio.com 2020-07-16 2020-07-16
IPv4 193.37.212.97 2020-07-16 2020-07-16
IPv4 85.217.171.87 2020-07-16 2020-07-16
IPv4 193.37.214.7 2020-07-16 2020-07-16
IPv4 85.209.88.123 2020-07-16 2020-07-16

Related Reports

2020-08-26 • 23% Match
#BeagleBoyz #FASTCash2 #T1082 #T1119 #T1090 #T1140 #T1005 #T1070.004 #T1041 #T1113 #T1020 #T1560 #T1115 #T1083 #T1036 #T1027 #T1071 #T1548.003 #T1204 #T1057 #T1059.005 #T1518.001 #T1566.001 #T1547.001 #T1059.001 #T1053 #T1132.001 #T1102 #T1059 #T1199 #T1105 #T1219 #T1055 #T1553.002 #T1552.004 #T1562.001 #T1486 #T1129 #T1489 #T1078 #T1133 #T1053.003 #T1190 #T1203 #T1189 #T1049 #T1098 #T1087 #T1016 #T1070.006 #T1021.001 #T1574.001 #T1217 #T1106 #T1573 #T1095 #T1056 #T1010 #T1021.002 #T1033 #T1569.002 #T1543.003 #T1485 #T1012 #T1110 #T1561.002 #T1202 #T1070.003 #T1565.001 #T1021 #T1505.003 #T1027.005 #T1056.004 #T1218.001 #T1562.003 #T1014 #T1053.004 #T1101 #T1565.002 #T1565.003 #T1562.006
Shares tags: T1082, T1005, T1113
« Back