APT-C-26

2016-08-25 • Qihoo360Lazarus(APT-C-26)

APT-C-26 is a designation used by Qihoo 360 for an activity cluster suspected of being operated by the Lazarus Group and directed against cryptocurrency institutions and individuals. In 2018, 360's Advanced Threat Response Team uncovered an attack in which the group distributed a trojanized cryptocurrency trading application built on an open-source trading tool, available for both Windows and macOS. The tampered software concealed a backdoor component that activated as soon as the program launched, collecting the victim's process list, computer name, and system information, encrypting it, and sending it to a command-and-control server, which could then return additional malicious code for execution. Continued monitoring by 360 found the same operators still active in 2019, having registered new lookalike domains and built a further trojanized automated-trading tool sharing the same code structure and attack framework as the earlier campaign. This later tool was promoted to staff at digital-currency exchanges as a phishing lure, leading to further compromises and theft of cryptocurrency assets, reflecting a sustained, financially motivated campaign against the cryptocurrency sector.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster