August 30, 2018 By Shane Schick 2 min read

Researchers observed an attack against a cryptocurrency exchange in which a Trojan spread across both Windows and MacOS machines to steal information and possibly digital coins.

Investigators at Kaspersky Lab attributed the attack, dubbed Operation AppleJeus, to a threat group known as Lazarus, which has a history of targeting fintech firms, banks and related organizations. In this case, however, users of a cryptocurrency exchange received emails that went to what looked like a legitimate site for a trading application from a company called Celas LLC.

Victims were encouraged to download an update that contained Fallchill, a remote access Trojan (RAT) that gave attackers complete control over an infected system by sending back information to a dedicated server.

A Cross-Platform Cryptocurrency Exchange Attack

While threat groups have tried to steal data from cryptocurrency users before, this is the first time Lazarus has been known to create malware that would infect those running MacOS machines.

For the most part, security researchers said the Trojanized updater for MacOS runs similarly to those using Windows devices, including the process of encrypting and transferring data. Given how many IT companies, engineers and others have begun to adopt technology from Apple, it’s not surprising that cybercriminals are adapting their malware tools accordingly.

According to Kaspersky Lab, a similar variant of Fallchill is being developed for Linux-based systems as well, which means security teams may need to be vigilant of potential threats across a wider variety of platforms.

How to Protect Against Phishing Attacks

The researchers said they couldn’t be sure whether the Celas LLC site was compromised by an outsider or created as a phony organization by Lazarus, which goes to show how easily regular victims can be duped. Campaigns like Operation AppleJeus are effective precisely because phishing sites are difficult to identify with the naked eye.

IBM experts suggest using technology that combines fraud-based detection with advanced phishing detection, alerts users to potentially dangerous sites and blocks them accordingly. Users should also update their antivirus software and look out for signs of the indicators of compromise (IoCs) listed in the IBM X-Force Exchange threat advisory for this Trojan.

Source: Kaspersky Lab

More from

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

4 ways to bring cybersecurity into your community

4 min read - It’s easy to focus on technology when talking about cybersecurity. However, the best prevention measures rely on the education of those who use technology. Organizations training their employees is the first step. But the industry needs to expand the concept of a culture of cybersecurity and take it from where it currently stands as an organizational responsibility to a global perspective.When every person who uses technology — for work, personal use and school — views cybersecurity as their responsibility, it…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today