Mac cryptocurrency trading application rebranded, bundled with malware
2020-07-16 • ESET •
ESET found malicious macOS cryptocurrency trading applications that copied or rebranded the legitimate Kattana app under names such as Licatrade and Cointrazer, continuing GMERA-style activity previously reported by Trend Micro. The trojanized bundles targeted cryptocurrency users by distributing fake trading apps from copycat websites, stealing browser cookies, cryptocurrency wallets, and screenshots while opening unencrypted reverse shells to attacker-controlled servers. The Licatrade sample reported victim details over HTTP to stepbystepby[.]com and attempted reverse-shell connections to 193.37.212[.]97 on ports including 25733 and 25734, with persistence attempted through a Launch Agent. Honeypot observations showed operators manually inspecting compromised Macs, collecting username, macOS version, location, hardware, display, and nearby Wi-Fi details before deciding whether the host was useful.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | e5d2c7fb4a64eaf444728e5c61f576f… | 2020-07-16 | 2020-07-16 |
| HASH | da1fda04d4149ebf93756bcef758eb8… | 2020-07-16 | 2020-07-16 |
| HASH | 4c688493958cc7cccfcb246e706184d… | 2020-07-16 | 2020-07-16 |
| HASH | 9c0d839d1f3da0577a123531e5b4503… | 2020-07-16 | 2020-07-16 |
| HASH | 1bc8ea284f9ce5f5f68c68531a410bc… | 2020-07-16 | 2020-07-16 |
| HASH | af65b1a945b517c4d8baaa706aa1923… | 2020-07-16 | 2020-07-16 |
| HASH | f6cd98a16e8cc2dd3ca1592d9911489… | 2020-07-16 | 2020-07-16 |
| HASH | b8f19b02f9218a8dd803da1f8650195… | 2020-07-16 | 2020-07-16 |
| HASH | 560071ef47fe5417fff62cb5c0e33b0… | 2020-07-16 | 2020-07-16 |
| HASH | 575a43504f79297cbfa900b55c12dc8… | 2020-07-16 | 2020-07-16 |
| HASH | 2ac42d9a11b67e8af7b610aa59aadcf… | 2020-07-16 | 2020-07-16 |
| HASH | bdbd92bff8e349452b07e5f1d288367… | 2020-07-16 | 2020-07-16 |
| [email protected] | 2020-07-16 | 2020-07-16 | |
| DOMAIN | trezarus.com | 2020-07-16 | 2020-07-16 |
| DOMAIN | cupatrade.com | 2020-07-16 | 2020-07-16 |
| DOMAIN | licatrade.com | 2020-07-16 | 2020-07-16 |
| DOMAIN | nagsrsdfsudinasa.com | 2020-07-16 | 2020-07-16 |
| DOMAIN | maccatreck.com | 2020-07-16 | 2020-07-16 |
| DOMAIN | latinumtrade.com | 2020-07-16 | 2020-07-16 |
| DOMAIN | narudina.com | 2020-07-16 | 2020-07-16 |
| DOMAIN | stepbystepby.com | 2020-07-16 | 2020-07-16 |
| DOMAIN | cointrazer.com | 2020-07-16 | 2020-07-16 |
| DOMAIN | creditfinelor.com | 2020-07-16 | 2020-07-16 |
| DOMAIN | apperdenta.com | 2020-07-16 | 2020-07-16 |
| DOMAIN | trezarus.net | 2020-07-16 | 2020-07-16 |
| DOMAIN | macstockfolio.com | 2020-07-16 | 2020-07-16 |
| IPv4 | 193.37.212.97 | 2020-07-16 | 2020-07-16 |
| IPv4 | 85.217.171.87 | 2020-07-16 | 2020-07-16 |
| IPv4 | 193.37.214.7 | 2020-07-16 | 2020-07-16 |
| IPv4 | 85.209.88.123 | 2020-07-16 | 2020-07-16 |