Lazarus group uses fake cryptocurrency apps to plant AppleJeus malware
2022-12-05 • Malwarebytes •
Malwarebytes summarized Volexity’s reporting on a Lazarus Group AppleJeus campaign targeting cryptocurrency users and organizations. The activity used the fake BloxHolder cryptocurrency application and a cloned HaasOnline-themed website at bloxholder[.]com to distribute a Windows MSI installer bundled with QTBitcoinTrader. The installer created a scheduled task to run CameraSettingsUIHost.exe and abused DLL side-loading through dui70.dll and malicious DUser.dll. The campaign fits Lazarus’s long-running use of trojanized cryptocurrency applications to gain access, deploy additional malware, and enable cryptocurrency theft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | rebelthumb.net | 2022-12-01 | 2024-09-18 |
| DOMAIN | strainservice.com | 2022-12-01 | 2023-10-26 |
| DOMAIN | wirexpro.com | 2022-12-01 | 2023-04-03 |
| DOMAIN | oilycargo.com | 2022-12-01 | 2023-04-03 |
| HASH | 18e190413af045db88dfbd29609eb877 | 2022-12-01 | 2022-12-05 |
| DOMAIN | telloo.io | 2022-12-01 | 2022-12-05 |
| DOMAIN | bloxholder.com | 2022-12-01 | 2022-12-05 |
Related Actors
Related Reports
Shares tag: AppleJeus • Shares 7 IOCs • Published within a week
Shares tag: AppleJeus • Shares 1 IOC • Published within a week
Shares tag: APT38
2023-01-23 •
50% Match
FBI Confirms Lazarus Group, APT38 Cyber Actors Responsible for Harmony's Horizon Bridge Currency Theft
USFBI
Shares tag: APT38
Shares tag: APT38
Shares tag: AppleJeus