MacOS Malware Surges as Corporate Usage Grows

2024-10-30 Trellix

https://www.trellix.com/blogs/research/macos-malware-surges-as-corporate-usage-grows/

Thumbnail for MacOS Malware Surges as Corporate Usage Grows

DPRK-aligned APT macOS activity In recent years, the Lazarus Group, a North Korean state-sponsored APT group , has intensified its focus on macOS, marking a significant shift in the macOS threat landscape. They employed advanced phishing campaigns themed around job recruitment, distributing signed malware disguised as legitimate job application files to macOS users in corporate environments. The ElectroRAT campaign, spanning into 2021, targeted cryptocurrency users across macOS, Windows, and Linux systems. Once installed, the malware established persistence on macOS systems via LaunchDaemons or LaunchAgents, granting Lazarus remote control and the ability to exfiltrate valuable data, including cryptocurrency wallet keys.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://support.internal-meetin… 2024-10-30 2024-10-30
URL http://maliciousdomain.com/malw… 2024-10-30 2024-10-30
DOMAIN maliciousdomain.com 2024-10-30 2024-10-30
IPv4 103.2.232.82 2024-10-30 2024-10-30
DOMAIN support.internal-meeting.site 2024-02-28 2024-10-30

Related Actors

Related Reports

« Back