AppleJeus Malware by Lazarus Targeting macOS, Windows Users Both: Kaspersky

Advertisement
By Tasneem Akolawala | Updated: 24 August 2018 18:24 IST
Highlights
  • Lazarus is infecting Mac and Windows machine in a new method
  • It is using a legit-looking cryptocurrency trading software to infect mac
  • This method gives attackers unlimited access to the computer

Lazarus used Trojanised cryptocurrencies exchanges to infect Mac machines.

Kaspersky researchers have uncovered a malware attack on Windows and macOS devices by the infamous Lazarus group. The group is apparently using Trojanised cryptocurrency exchanges to spread malware on laptops, including macOS devices. This new operation has been given the term AppleJeus, as it's the first time Lazarus has been reported to distributing malware on macOS machines. An attack was recognised in Asia, where the attackers penetrated the network of a cryptocurrency exchange using Trojanised cryptocurrency trading software.

The Lazarus group is thought to have links to North Korea, and a government funded threat group. This recent attack was done with the aim to steal cryptocurrency. Kaspersky notes that this is the first time it has seen a Lazarus distributed malware targeting macOS users as well, and said "it represents a wakeup call for everyone who uses this OS for cryptocurrency-related activity."

It is learnt that the malware arrives on a computer through an update to a third-party software app appearing to be for cryptocurrency trading. Kaspersky notes that it began when a company employee downloaded an app from a legitimate looking company website. This application sent information to back to the command and control server, and once the attackers ascertained that the computer is worth infecting, it sent malicious code in the form of a software update. The Trojan Fallchill is then installed on to the computer, and it gives attackers unlimited access to steal valuable financial information or to deploy additional tools for that purpose.

Advertisement

The AppleJeus operation was possible because of the seemingly legit looking cryptocurrency trading software that was installed. Kaspersky notes that the software vendor even has a valid digital certificate for signing its software and legitimate looking registration records for the domain.

Advertisement

Kaspersky recommends users tread with caution while installing any software related to cryptocurrency. "Do not automatically trust the code running on your systems. Neither an authentic looking website, nor a solid company profile, nor digital certificates guarantee the absence of backdoors," it added. The security firm also advised to use a robust security solution, equipped with malicious-behaviour detection technologies that enable even previously unknown threats to be caught. Also, it would be beneficial to use multi-factor authentication and hardware wallets if you are dealing with significant financial transactions. For this purpose, preferably use a standalone, isolated computer that you do not use to browse the Internet or read email.

Cybercriminal gang Lazarus is believed to be behind large scale cyber-attacks across the world including recent WannaCry ransomware, and it was also reported to have access to few servers in India as well.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Lazarus, Applejeus
Advertisement

Related Stories

Popular Mobile Brands
  1. Google's Pixel Phones Get a Second December Update With These Fixes
  2. OnePlus 15R Review
  3. Hogwarts Legacy Tops 40 Million Copies Sold
  4. Xiaomi 17 Ultra With Leica-Tuned Cameras Confirmed to Launch Soon
  5. OnePlus 15s Visits BIS Certification Website; Could Launch in India Soon
  6. OnePlus 15R With 7,400mAh Battery, Snapdragon 8 Gen 5 Debuts at This Price
  7. You Can Now Vibe Code AI Mini Apps Within Gemini With This Tool
  8. Nvidia's GeForce RTX 50 Series GPUs Are About to Be Scarce
  9. OnePlus Pad Go 2 Launched in India With 10,050mAh Battery, 5G Connectivity
  10. Hackers Threaten to Expose Pornhub's Sensitive User Data
  1. OpenAI Starts Reviewing Third-Party App Submissions for ChatGPT Integration
  2. Google Brings Opal, an AI-Powered Mini App Builder Tool to Gemini
  3. Redmi Pad 2 Pro 5G India Launch Teased Soon After Global Debut: Expected Specifications, Features
  4. CES 2026: Samsung to Unveil Bespoke AI Laundry Combo, Jet Bot Steam Ultra Robot Vacuum, and More
  5. Samsung Exynos 2600 Details Leak Ahead of Galaxy S26 Launch; Could Be Equipped With 10-Core CPU, AMD GPU
  6. Vivo Y50e 5G, Vivo Y50s 5G Appear on Google Play Console; Mysterious Vivo Phone Listed on Certification Site
  7. Nvidia to Reportedly Cut GeForce RTX 50 Series GPU Production Amid Global RAM Shortage
  8. Apple Allows Third-Party App Stores, Relaxes Payment Restrictions in Japan to Comply With MSCA Act
  9. Hogwarts Legacy Has Sold 40 Million Copies, Warner Bros. Games Announces
  10. OnePlus 15s Listing on BIS Certification Website Hints at Imminent Launch in India
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.