MAR-10322463-1.v1 - AppleJeus: Celas Trade Pro
2021-02-17 • USCISA •
CISA, the FBI, and the U.S. Treasury attribute the Trojanized Celas Trade Pro cryptocurrency application to North Korean state-sponsored Lazarus Group activity. Windows and macOS installers presented a functional clone of QT Bitcoin Trader while adding an updater that collected host data, contacted celasllc.com, and decrypted returned payloads. The operation ultimately delivered FALLCHILL, a HIDDEN COBRA remote-access Trojan, and used phishing and a professionally presented cryptocurrency website to reach victims.
Indicators of Compromise
Related Actors
Related Reports
Shares tags: AppleJeus, macOS, Lazarus • Same author: USCISA • Published within a week
Shares tags: AppleJeus, macOS, Lazarus • Same author: USCISA • Published within a week
Shares tags: AppleJeus, macOS, Lazarus • Same author: USCISA • Published within a week
Shares tags: AppleJeus, macOS, Lazarus • Same author: USCISA • Published within a week
Shares tags: AppleJeus, macOS, Lazarus • Same author: USCISA • Published within a week
Shares tags: AppleJeus, macOS, Lazarus • Same author: USCISA • Published within a week