Pass the AppleJeus
2019-10-12 • Objective-see •
Objective-See analyzed a macOS backdoor that the post attributes to Lazarus and ties to the AppleJeus-style use of fake cryptocurrency trading software. The JMT Trading campaign used a legitimate-looking website and GitHub release downloads to distribute JMTTrader_Mac.dmg, which installed hidden LaunchDaemon and CrashReporter components under /Library/JMTTrader after requesting administrator privileges. The persistence plist ran CrashReporter with the Maintain argument, and the sample is described as a Mach-O 64-bit executable with an ad-hoc signature, a Chrome-like user agent, multipart form-data strings, and likely download or C2-related strings. The activity matters for DPRK-focused tracking because it shows Lazarus continuing to package macOS malware inside convincing crypto-trading applications rather than relying only on Windows payloads.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | beastgoc.com | 2019-10-12 | 2021-02-18 |
| IPv4 | 185.228.83.32 | 2019-10-12 | 2020-01-08 |
| URL | https://www.jmttrading.org/ | 2019-10-12 | 2020-01-01 |
| URL | https://beastgoc.com/grepmonux.… | 2019-10-12 | 2020-01-01 |
| HASH | 74390fba9445188f2489959cb289e73… | 2019-10-12 | 2019-10-12 |