logo

North Korea’s Lazarus Tied to Cryptojacking Campaign Targeting MacOS

ID: 37b5a986-2fe6-59de-935e-bc8300fa6056

STIX ID: report--37b5a986-2fe6-59de-935e-bc8300fa6056

Feed Name: Security Ledger

Threat Score
88/100

Date Published: 2018-08-29

Date Updated: 2026-04-26

Author: Elizabeth Montalbano

...
...

Kaspersky uncovered an AppleJeus campaign attributed to North Korea’s Lazarus group in which attackers trojanized a legitimate cryptocurrency trading application (Celas Trade Pro) to push Fallchill and platform-specific malware—marking Lazarus’ first observed macOS tooling. The spear-phishing supply-chain-style attack led to infection of at least one bank/exchange environment when an employee ran an updater that collected host information and contacted attacker infrastructure, highlighting expansion to non‑Windows platforms and continued targeting of the financial/cryptocurrency sector.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.