Operation AppleJeus – Lazarus APT Hackers Launching Highly Sophisticated Malware To Attack Windows & macOS Systems

Researchers discovered an ongoing sophisticated and heavily deformed malware campaign called “AppleJeus” launched by one of the world’s most active and notorious Hackers group Lazarus to target both Windows and macOS users.

Lazarus hackers initially started their AppleJues malware campaign in 2018, since then they have made significant changes in their attack methodology, and currently developed homemade macOS malware.

This new variant has added with authentication mechanism to deliver the next stage payload very carefully and load it without touching the disk.

To attack windows users, they have equipped the malware with a multi-stage infection procedure and significantly changed the final payload.

AppleJeus campaign mainly targeting the cryptocurrency businesses by continuously using the similar modus operandi, and it using the used public source code in order to build crafted macOS installers.

By analyzing the ongoing campaign, researchers uncovered that the attackers also compromised by Windows AppleJeus, but the couldn’t identify the initial stage of the installer.

AppleJeus Infection Process

A multi-stage infection process used to attack the windows based systems, and it starts with .NET malware that mimics WFC wallet updater.

The malware is responsible for decrypting the file ” WFC.cfg” and the wallet updater connected to the C2 and it solves the following IP.

  • wfcwallet.com (resolved ip: 108.174.195.134)
  • www.chainfun365.com (resolved ip: 23.254.217.53)

Later attackers utilizing the command line parameter to establish remote tunneling, the actor delivered more hacking tools and also researchers from Kaspersky identified the CenterUpdater.exe tool was used for creating tunneling to a remote host.

Researchers also found the Windows version of the UnionCryptoTrader and it utilizes the Telegram messenger for its execution process and their telegram group was identified in their fake website.

Kaspersky’s research team believed that the actor delivered the manipulated installer using the Telegram messenger.

The overall infection procedure was very similar to the WFCWallet case, but with an added injection procedure, and they only used the final backdoor payload instead of using a tunneling tool.

In the macOS malware, attackers called their fake website and application JMTTrading and the various other vendors have been reported about the mac version of AppleJues malware and the malicious application name, in this case, is UnionCryptoTrader.

Kaspersky researchers found several fake websites that represent the cryptocurrency trading, that was built by free web templates.

AppleJeus attacked several victims around the globe including the UK, Poland, Russia and China and also several victims are linked with cryptocurrency business entities.

The actor altered their macOS and Windows malware considerably, adding an authentication mechanism in the macOS downloader and changing the macOS development framework. Kaspersky said.

Also Read: Heavily Obfuscated Malware Campaign using Weaponized PowerPoint Files to Drop Lokibot & Azorult

Balaji N

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago