Pass the AppleJeus

2019-10-12 Objective-see

https://objective-see.com/blog/blog_0x49.html

Thumbnail for Pass the AppleJeus

Objective-See analyzed a macOS backdoor that the post attributes to Lazarus and ties to the AppleJeus-style use of fake cryptocurrency trading software. The JMT Trading campaign used a legitimate-looking website and GitHub release downloads to distribute JMTTrader_Mac.dmg, which installed hidden LaunchDaemon and CrashReporter components under /Library/JMTTrader after requesting administrator privileges. The persistence plist ran CrashReporter with the Maintain argument, and the sample is described as a Mach-O 64-bit executable with an ad-hoc signature, a Chrome-like user agent, multipart form-data strings, and likely download or C2-related strings. The activity matters for DPRK-focused tracking because it shows Lazarus continuing to package macOS malware inside convincing crypto-trading applications rather than relying only on Windows payloads.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN beastgoc.com 2019-10-12 2021-02-18
IPv4 185.228.83.32 2019-10-12 2020-01-08
URL https://www.jmttrading.org/ 2019-10-12 2020-01-01
URL https://beastgoc.com/grepmonux.… 2019-10-12 2020-01-01
HASH 74390fba9445188f2489959cb289e73… 2019-10-12 2019-10-12

Related Actors

Related Reports

« Back