11 Dec Lazarus Group Targets macOS Users With Fileless Malware Threat
[ad_1]
MacOS computer users are being targeted by the Lazarus hacker collective with fileless malware that’s designed to resemble a cryptocurrency trading app.
Best known as the group linked to major cyberattacks such as WannaCry and the hack on Sony Pictures Entertainment, the latest campaign from Lazarus involves trojanizing an open-source Apple software application to steal cryptocurrency, according to a report from K7 Labs.
The infection process starts by writing files to a disk, after which its final executable loads directly onto memory. This classifies the threat as fileless malware, researchers explained.
The AppleJeus Attack Close Up
Known as OSX.AppleJeus.C, the malware connects to a remote server to receive a payload from Lazarus while continuing to run out of the infected machine’s main memory.
A trojanized version of UnionCryptoTrader.dmg, another cryptocurrency trading container, was also discovered as part of the investigation. Researchers said the campaign may…
[ad_2]
Source link