Friday, January 27, 2023
TopCrytpoNews.com
Shop
No Result
View All Result
  • Home
  • Cryptocurrency
  • Blockchain
  • Market & Analysis
  • Bitcoin
  • Altcoins
  • Dogecoin
  • Ethereum
  • Litecoin
  • Solana
TopCrytpoNews.com
No Result
View All Result
Home Cryptocurrency

Lazarus APT uses fake cryptocurrency apps to spread AppleJeus MalwareSecurity Affairs

Mikhailev by Mikhailev
December 5, 2022
in Cryptocurrency
0
Lazarus APT uses fake cryptocurrency apps to spread AppleJeus MalwareSecurity Affairs
Share on FacebookShare on Twitter


The North Korea-linked Lazarus APT spreads pretend cryptocurrency apps beneath the pretend model BloxHolder to put in the AppleJeus malware.

Volexity researchers warn of a brand new malware marketing campaign performed by the North Korea-linked Lazarus APT towards cryptocurrency customers. The menace actors have been noticed spreading pretend cryptocurrency apps beneath the pretend model BloxHolder to ship the AppleJeus malware for preliminary entry to networks and steal crypto property.

The APT group employed the AppleJeus malware since at the least 2018 to steal cryptocurrencies from the victims.

The brand new marketing campaign noticed by Volexity began in June 2022, the APT group registered the area identify bloxholder[.]com, after which arrange an internet site associated to automated cryptocurrency buying and selling.

The brand new marketing campaign attributed to Lazarus began in June 2022 and was lively till at the least October 2022.

On this marketing campaign, the menace actors used the “bloxholder[.]com” area, a clone of the HaasOnline automated cryptocurrency buying and selling platform.

The web site is a clone of the professional web site, HaasOnline (haasonline[.]com.)

Volexity_AppleJeus Lazarus Figure-01-2048x899

The attackers used the web site to distribute a Home windows MSI installer masquerading because the BloxHolder app, which was used to put in AppleJeus malware together with the QTBitcoinTrader app.

“This found file, the  “BloxHolder utility”, is definitely one other case of AppleJeus being put in alongside the open-source cryptocurrency buying and selling utility QTBitcoinTrader that’s available on GitHub. This identical professional utility has beforehand been utilized by the Lazarus Group, as documented in this report from CISA.” reads the report printed by Volexity. “The MSI file is used to put in each the malicious and bonafide purposes on the identical time.”

In October 2022, the researchers noticed the Lazarus Group putting in AppleJeus utilizing a weaponized Microsoft Workplace doc, named ‘OKX Binance & Huobi VIP payment comparision.xls,’ as a substitute of an MSI installer.

The doc accommodates a macro break up into two components, the primary one is used to decode a base64 blob that accommodates a second OLE object containing a second macro. The preliminary doc additionally shops a number of variables, encoded utilizing base64, that enable defining the place the malware shall be deployed within the contaminated system.

The final stage payload is downloaded from a public file-sharing service, OpenDrive. 

Volexity specialists weren’t in a position to retrieve the ultimate payload employed since October, however they seen similarities within the DLL sideloading mechanism which has similarities to the one used within the assaults counting on MSI installer.

“Whereas the file was now not out there on the time of study, primarily based on public sandbox outcomes for the file in query, the downloaded payload, “Background.png”, embeds the next three information:

  • “Logagent.exe” – a professional file (md5: eb1e19613a6a260ddd0ae9224178355b)
  • “wsock32.dll” – a side-loaded library internally named HijackingLib.dll (md5: e66bc1e91f1a214d098cf44ddb1ae91a)
  • “56762eb9-411c-4842-9530-9922c46ba2da” – an encoded payload decoded by “wsock32.dll”

“continues the evaluation. “The three information are dropped on disk utilizing hardcoded offsets that may be discovered within the second macro.”

Consultants speculate Lazarus used DLL sideloading to keep away from malware evaluation, the menace actors additionally seen that current AppleJeus samples obfuscated strings and API calls utilizing a customized algorithm.

“The Lazarus Group continues its effort to focus on cryptocurrency customers, regardless of ongoing consideration to their campaigns and techniques. Maybe in an try to allude detection, they’ve determined to make use of chained DLL side-loading to load their payload. Moreover, Volexity has not beforehand famous using Microsoft Workplace paperwork to deploy AppleJeus variants.” concludes volexity. “Regardless of these adjustments, their targets stay the identical, with the cryptocurrency trade being a spotlight as a way for the DPRK to bolster their funds.”

Comply with me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, APT)

Related articles

Solana Looks to Sever Bankman-Fried Connection

Leaders Say Crypto’s New Year Ripe for Rebuilding 

January 27, 2023
Experts Explain How Gen Z’s Interest in Crypto Will Affect the Future of Banking

Experts Explain How Gen Z’s Interest in Crypto Will Affect the Future of Banking

January 27, 2023



Share On






Source link

Share76Tweet47

Related Posts

Solana Looks to Sever Bankman-Fried Connection

Leaders Say Crypto’s New Year Ripe for Rebuilding 

by Mikhailev
January 27, 2023
0

It’s occasions like these, bear markets, when industries remodel themselves round new realities. That is as prime fee business leaders surveyed by...

Experts Explain How Gen Z’s Interest in Crypto Will Affect the Future of Banking

Experts Explain How Gen Z’s Interest in Crypto Will Affect the Future of Banking

by Mikhailev
January 27, 2023
0

Worawee Meepian / Getty Photos/iStockphotoCryptocurrency, so far as Gen Z is anxious, has a spot in the way forward for...

Cryptocurrency ATM Market is Expected to Grow at a Massive CAGR of 45.8% by 2027

Cryptocurrency ATM Market is Expected to Grow at a Massive CAGR of 45.8% by 2027

by Mikhailev
January 27, 2023
0

Report Abstract: The Cryptocurrency ATM Market Analysis Report supplies intensive data on the next subjects: Trade measurement, share, development, segmentation,...

Solana Looks to Sever Bankman-Fried Connection

Crypto Subcommittee Aims for ‘Responsible Innovation’

by Mikhailev
January 27, 2023
0

Cryptocurrency trade regulation within the post-FTX period has emerged as a urgent concern for the brand new Congress. It's no...

Data shows pro Bitcoin traders want to feel bullish, but the rally to $23K wasn’t enough

Data shows pro Bitcoin traders want to feel bullish, but the rally to $23K wasn’t enough

by Mikhailev
January 27, 2023
0

Bitcoin (BTC) value had a blended response on Jan. 25 after the US reported a 2.9% gross home product progress...

Load More
  • Trending
  • Comments
  • Latest
Square Enix NFT And Blockchain Plans Laid Out In Annual Report

Square Enix NFT And Blockchain Plans Laid Out In Annual Report

May 13, 2022
Is Austin, Texas About to Lead the US in Blockchain, Crypto and Sustainability? With Mission 6, it Appears So

Is Austin, Texas About to Lead the US in Blockchain, Crypto and Sustainability? With Mission 6, it Appears So

May 13, 2022
Jack Dorsey Names Reason for Next Bitcoin Price Surge

438.4 Million Dogecoin Moved to Robinhood for Fee That Easily Beats Any Bank

May 22, 2022
Top LTC Online Gambling Sites for 2022

Top LTC Online Gambling Sites for 2022

May 15, 2022
Japan’s Nomura dives into cryptocurrency derivatives trading (NYSE:NMR)

Japan’s Nomura dives into cryptocurrency derivatives trading (NYSE:NMR)

0
Cryptocurrency Avalanche’s Price Increased More Than 8% Within 24 hours

Cryptocurrency Avalanche’s Price Increased More Than 8% Within 24 hours

0
Bitcoin & Cryptocurrency Take Massive Nose Dive

Bitcoin & Cryptocurrency Take Massive Nose Dive

0
Todd Snider talks life on the road making music ahead of Southern California dates – Daily News

Todd Snider talks life on the road making music ahead of Southern California dates – Daily News

0
Solana Looks to Sever Bankman-Fried Connection

Leaders Say Crypto’s New Year Ripe for Rebuilding 

January 27, 2023
Solana (SOL) and Chronoly.io (CRNO) By DailyCoin

Three Well-Known Altcoins That Traders Should Keep An Eye On By CoinEdition

January 27, 2023
Aave deploys V3 on Ethereum after 10 months of testing on other networks

Aave deploys V3 on Ethereum after 10 months of testing on other networks

January 27, 2023
Bitcoin Breakout Imminent? Analyst Says Key Price Point Will Be Pivotal, Tracks Path Ahead for Litecoin and Three Ethereum-Based Altcoins

Bitcoin Breakout Imminent? Analyst Says Key Price Point Will Be Pivotal, Tracks Path Ahead for Litecoin and Three Ethereum-Based Altcoins

January 27, 2023

Recent News

Solana Looks to Sever Bankman-Fried Connection

Leaders Say Crypto’s New Year Ripe for Rebuilding 

January 27, 2023
Solana (SOL) and Chronoly.io (CRNO) By DailyCoin

Three Well-Known Altcoins That Traders Should Keep An Eye On By CoinEdition

January 27, 2023
Aave deploys V3 on Ethereum after 10 months of testing on other networks

Aave deploys V3 on Ethereum after 10 months of testing on other networks

January 27, 2023

Categories

  • Altcoins
  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Dogecoin
  • Ethereum
  • Litecoin
  • Market & Analysis
  • Solana

Follow Us

Tags

Avalanche bitcoin bitcoin price bitcoin price in india bitcoin price today Blockchain Blockchain Wire business Business news Cardano Crypto Crypto Coins CryptoCurrencies Cryptocurrency cryptocurrency news cryptocurrency price today crypto market crypto news crypto price in india crypto price today Culture DeFi Dogecoin Dogecoin price ETH Ethereum fintech FTX investing Litecoin Markets News NFT Opinion Ripple SEO Shiba shiba inu Shiba Inu Price SOL Solana solana price TECH Technical Analysis Technology
  • Contact Us

© 2022 Top Crypto News - All rights reserved.

No Result
View All Result
  • Home
  • Cryptocurrency
  • Blockchain
  • Market & Analysis
  • Bitcoin
  • Altcoins
  • Dogecoin
  • Ethereum
  • Litecoin
  • Solana

© 2022 Top Crypto News - All rights reserved.