Monday, January 30, 2023
cryptonews100
No Result
View All Result
CryptoNews100
No Result
View All Result
Home Cryptocurrency

Lazarus APT uses fake cryptocurrency apps to spread AppleJeus MalwareSecurity Affairs

cryptonews100_tggfrn by cryptonews100_tggfrn
December 5, 2022
in Cryptocurrency
0
Lazarus APT uses fake cryptocurrency apps to spread AppleJeus MalwareSecurity Affairs
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


The North Korea-linked Lazarus APT spreads fake cryptocurrency apps below the fake model BloxHolder to set up the AppleJeus malware.

Volexity researchers warn of a brand new malware marketing campaign carried out by the North Korea-linked Lazarus APT towards cryptocurrency customers. The risk actors had been noticed spreading fake cryptocurrency apps below the fake model BloxHolder to ship the AppleJeus malware for preliminary entry to networks and steal crypto property.

The APT group employed the AppleJeus malware since at the least 2018 to steal cryptocurrencies from the victims.

The brand new marketing campaign noticed by Volexity began in June 2022, the APT group registered the area title bloxholder[.]com, after which arrange a web site associated to automated cryptocurrency buying and selling.

The brand new marketing campaign attributed to Lazarus began in June 2022 and was energetic till at the least October 2022.

On this marketing campaign, the risk actors used the “bloxholder[.]com” area, a clone of the HaasOnline automated cryptocurrency buying and selling platform.

The web site is a clone of the respectable web site, HaasOnline (haasonline[.]com.)

Volexity_AppleJeus Lazarus Figure-01-2048x899

The attackers used the web site to distribute a Home windows MSI installer masquerading because the BloxHolder app, which was used to set up AppleJeus malware together with the QTBitcoinTrader app.

“This found file, the  “BloxHolder software”, is definitely one other case of AppleJeus being put in alongside the open-source cryptocurrency buying and selling software QTBitcoinTrader that’s available on GitHub. This similar respectable software has beforehand been utilized by the Lazarus Group, as documented in this report from CISA.” reads the report printed by Volexity. “The MSI file is used to set up each the malicious and legit functions on the similar time.”

In October 2022, the researchers noticed the Lazarus Group putting in AppleJeus utilizing a weaponized Microsoft Workplace doc, named ‘OKX Binance & Huobi VIP price comparision.xls,’ as a substitute of an MSI installer.

The doc incorporates a macro cut up into two elements, the primary one is used to decode a base64 blob that incorporates a second OLE object containing a second macro. The preliminary doc additionally shops a number of variables, encoded utilizing base64, that enable defining the place the malware might be deployed within the contaminated system.

The final stage payload is downloaded from a public file-sharing service, OpenDrive. 

Volexity consultants weren’t in a position to retrieve the ultimate payload employed since October, however they observed similarities within the DLL sideloading mechanism which has similarities to the one used within the assaults counting on MSI installer.

“Whereas the file was not obtainable on the time of study, based mostly on public sandbox outcomes for the file in query, the downloaded payload, “Background.png”, embeds the next three information:

  • “Logagent.exe” – a respectable file (md5: eb1e19613a6a260ddd0ae9224178355b)
  • “wsock32.dll” – a side-loaded library internally named HijackingLib.dll (md5: e66bc1e91f1a214d098cf44ddb1ae91a)
  • “56762eb9-411c-4842-9530-9922c46ba2da” – an encoded payload decoded by “wsock32.dll”

“continues the evaluation. “The three information are dropped on disk utilizing hardcoded offsets that may be discovered within the second macro.”

Consultants speculate Lazarus used DLL sideloading to keep away from malware evaluation, the risk actors additionally observed that current AppleJeus samples obfuscated strings and API calls utilizing a customized algorithm.

“The Lazarus Group continues its effort to goal cryptocurrency customers, regardless of ongoing consideration to their campaigns and techniques. Maybe in an try to allude detection, they’ve determined to use chained DLL side-loading to load their payload. Moreover, Volexity has not beforehand famous the usage of Microsoft Workplace paperwork to deploy AppleJeus variants.” concludes volexity. “Regardless of these adjustments, their targets stay the identical, with the cryptocurrency trade being a spotlight as a method for the DPRK to bolster their funds.”

Observe me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, APT)



Share On






Source link

Related articles

Budget 2023 | Revisit tax policy on cryptocurrency, bring new laws for virtual digital assets

Budget 2023 | Revisit tax policy on cryptocurrency, bring new laws for virtual digital assets

January 30, 2023
Bitcoin Prices Have Climbed Over 50% Since Bottoming Last Year

Bitcoin Prices Have Climbed Over 50% Since Bottoming Last Year

January 29, 2023
Tags: affairsAppleJeusappsAPTCryptocurrencyfakeLazarusMalwareSecurityspread
Share76Tweet47
kucoin-exchange

Related Posts

Budget 2023 | Revisit tax policy on cryptocurrency, bring new laws for virtual digital assets

Budget 2023 | Revisit tax policy on cryptocurrency, bring new laws for virtual digital assets

by cryptonews100_tggfrn
January 30, 2023
0

The Authorities of India’s considerations over cryptocurrencies have been rising, which it primarily attributes to terror-financing and money-laundering. This has...

Bitcoin Prices Have Climbed Over 50% Since Bottoming Last Year

Bitcoin Prices Have Climbed Over 50% Since Bottoming Last Year

by cryptonews100_tggfrn
January 29, 2023
0

Bitcoin costs have rallied sharply in the previous couple of months. (Picture by Nicolas Economou/NurPhoto by way of ... Getty...

Forex and Cryptocurrency Forecast: Five Days of Storms and Tsunamis

Forex and Cryptocurrency Forecast: Five Days of Storms and Tsunamis

by cryptonews100_tggfrn
January 29, 2023
0

EUR/USD: Subsequent week: Five Days of Storms and Tsunamis Plainly the entire world celebrated the Chinese language New Yr final...

White House Publishes ‘Roadmap’ to Mitigate Cryptocurrency Risks – Regulation Bitcoin News

White House Publishes ‘Roadmap’ to Mitigate Cryptocurrency Risks – Regulation Bitcoin News

by cryptonews100_tggfrn
January 29, 2023
0

The White House has revealed a “roadmap to mitigate cryptocurrencies’ dangers.” The roadmap requires authorities to “ramp up enforcement the...

Cryptocurrency for dummies: Everything you need to know about digital assets

Cryptocurrency for dummies: Everything you need to know about digital assets

by cryptonews100_tggfrn
January 28, 2023
0

Attempt to keep away from all of it you like, however 'cryptocurrency', 'Bitcoin' and 'NFTs' will all the time discover...

Load More
""

Crypto Fear & Greed Index

Latest Crypto Fear & Greed Index

Recent News

Polkadot, Ethereum & Orbeon Protocol: 3 Cryptocurrencies to Look Out For in 2023

Polkadot, Ethereum & Orbeon Protocol: 3 Cryptocurrencies to Look Out For in 2023

January 30, 2023
Cardano, Bitcoin Lead Returns for Major Coins in 2023 – BSC NEWS

Cardano, Bitcoin Lead Returns for Major Coins in 2023 – BSC NEWS

January 30, 2023
Ethereum & Big Eyes Coin in the new year

Ethereum & Big Eyes Coin in the new year

January 30, 2023

Categories

  • Alt Coins
  • Bitcoin
  • Blockchain
  • Cardano
  • Chainlink
  • Cryptocurrency
  • Dogecoin
  • Elon Musk
  • Ethereum
  • ICO
  • Litecoin
  • Market & Analysis
  • Pokadot
  • Polygon
  • Shiba Inu
  • Solana
  • Terra Luna
  • The FED
  • Uncategorized
  • VeChain
  • XRP

Download the official CryptoNews100 Android App! Click the button below:

Tags

ADA (546) Big (492) Bitcoin (3922) blockchain (933) BTC (644) Buy (464) Cardano (1304) ChainLink (431) coin (779) Cointelegraph (330) crypto (3587) Cryptocurrencies (438) Cryptocurrency (1658) Cryptos (353) DOGE (660) Dogecoin (1691) Elon (424) ETH (512) Ethereum (2145) eyes (386) Heres (373) Inu (1301) investors (358) Litecoin (625) LUNA (356) market (1303) Musk (365) News (1029) NFT (429) Polkadot (549) POLYGON (628) prediction (381) price (2065) prices (367) Ripple (437) SHIB (498) Shiba (1321) Solana (1068) Terra (395) today (564) token (471) top (680) VeChain (641) VET (333) XRP (778)

© 2021 Crypto News100 All Rights Reserved.
By visiting this website, you understand that the content provided within is for educational and entertainment purposes only. Nothing on this site may be constituted as financial advice and this site is not directing you to make any investments in cryptocurrency or in anything else. Thank you for visiting and please proceed responsibly.
As an Amazon Associate I earn from qualifying purchases.

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Alt Coins
    • Cardano
    • Dogecoin
    • Litecoin
    • Pokadot
    • Polygon
    • Shiba Inu
    • Terra Luna
    • Solana
    • XRP
    • VeChain
  • Market & Analysis
    • Blockchain
    • The FED
    • ICO
  • Profit with Crypto
    • Crypto Exchanges
    • Crypto Interest-Earning Accounts
    • Crypto Retirement Accounts

© 2021 Crypto News100 All Rights Reserved.
By visiting this website, you understand that the content provided within is for educational and entertainment purposes only. Nothing on this site may be constituted as financial advice and this site is not directing you to make any investments in cryptocurrency or in anything else. Thank you for visiting and please proceed responsibly.
As an Amazon Associate I earn from qualifying purchases.