Brief Analysis on APT Attack through Cryptocurrency Trading Software

2018-08-15 Qihoo360

http://blogs.360.cn/blog/apt-c-26/

360 Core Security attributed a cryptocurrency-sector attack, tracked as APT-C-26 and suspected to involve Lazarus, to trojanized digital currency trading software named Celas Trade Pro. The attackers modified the open source Qt Bitcoin Trader application by adding an updater backdoor and promoted the fake trading software to cryptocurrency institutions and related individuals. The Windows and macOS versions collected process lists, computer names, and system information, encrypted the data, sent it to a server, and executed malicious code returned by the server. The report identifies celasllc.com/checkupdate.php and sample hashes as key indicators, highlighting continued targeting of cryptocurrency users and organizations for financially motivated operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 5e54bccbd4d93447e79cda0558b0b30… 2018-08-15 2021-02-18
HASH bdff852398f174e9eef1db1c2d3fefd… 2018-08-15 2021-02-18
URL https://www.celasllc.com/checku… 2018-08-15 2018-08-23

Related Actors

Related Reports

« Back