MacOS Malware Surges as Corporate Usage Grows
2024-10-30 • Trellix •
https://www.trellix.com/blogs/research/macos-malware-surges-as-corporate-usage-grows/
DPRK-aligned APT macOS activity In recent years, the Lazarus Group, a North Korean state-sponsored APT group , has intensified its focus on macOS, marking a significant shift in the macOS threat landscape. They employed advanced phishing campaigns themed around job recruitment, distributing signed malware disguised as legitimate job application files to macOS users in corporate environments. The ElectroRAT campaign, spanning into 2021, targeted cryptocurrency users across macOS, Windows, and Linux systems. Once installed, the malware established persistence on macOS systems via LaunchDaemons or LaunchAgents, granting Lazarus remote control and the ability to exfiltrate valuable data, including cryptocurrency wallet keys.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://support.internal-meetin… | 2024-10-30 | 2024-10-30 |
| URL | http://maliciousdomain.com/malw… | 2024-10-30 | 2024-10-30 |
| DOMAIN | maliciousdomain.com | 2024-10-30 | 2024-10-30 |
| IPv4 | 103.2.232.82 | 2024-10-30 | 2024-10-30 |
| DOMAIN | support.internal-meeting.site | 2024-02-28 | 2024-10-30 |