logo

₿uyer ₿eware: Fake Cryptocurrency Applications Serving as Front for AppleJeus Malware

ID: 55db9864-5352-552a-9aed-25842301bc0f

STIX ID: report--55db9864-5352-552a-9aed-25842301bc0f

Feed Name: Volexity Blog

Threat Score
85/100

Date Published: 2022-12-01

Date Updated: 2026-05-01

...
...

Volexity documents a June–October 2022 Lazarus Group campaign targeting cryptocurrency users by distributing backdoored cryptocurrency applications (MSI) and malicious Microsoft Office documents that deploy AppleJeus variants; notable findings include a cloned cryptocurrency website (bloxholder.com), a novel chained DLL side-loading technique where a system DLL loads an attacker DLL, obfuscated AppleJeus variants, C2 hostnames and numerous file IOCs, plus recommended detections and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.