₿uyer ₿eware: Fake Cryptocurrency Applications Serving as Front for AppleJeus Malware
ID: 55db9864-5352-552a-9aed-25842301bc0f
STIX ID: report--55db9864-5352-552a-9aed-25842301bc0f
Feed Name: Volexity Blog
Volexity documents a June–October 2022 Lazarus Group campaign targeting cryptocurrency users by distributing backdoored cryptocurrency applications (MSI) and malicious Microsoft Office documents that deploy AppleJeus variants; notable findings include a cloned cryptocurrency website (bloxholder.com), a novel chained DLL side-loading technique where a system DLL loads an attacker DLL, obfuscated AppleJeus variants, C2 hostnames and numerous file IOCs, plus recommended detections and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
