North Korea’s Lazarus Tied to Cryptojacking Campaign Targeting MacOS
ID: 37b5a986-2fe6-59de-935e-bc8300fa6056
STIX ID: report--37b5a986-2fe6-59de-935e-bc8300fa6056
Feed Name: Security Ledger
Kaspersky uncovered an AppleJeus campaign attributed to North Korea’s Lazarus group in which attackers trojanized a legitimate cryptocurrency trading application (Celas Trade Pro) to push Fallchill and platform-specific malware—marking Lazarus’ first observed macOS tooling. The spear-phishing supply-chain-style attack led to infection of at least one bank/exchange environment when an employee ran an updater that collected host information and contacted attacker infrastructure, highlighting expansion to non‑Windows platforms and continued targeting of the financial/cryptocurrency sector.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
