Lazarus group uses fake cryptocurrency apps to plant AppleJeus malware

Home/BOTNET, Compromised, Data Breach, Exploitation, Internet Security, IOC's, malicious cyber actors, Security Advisory, Security Update/Lazarus group uses fake cryptocurrency apps to plant AppleJeus malware

Lazarus group uses fake cryptocurrency apps to plant AppleJeus malware

Lazarus hacking group spreads malware using a fake cryptocurrency app called BloxHolder. This made-up brand pretends to offer cryptocurrency applications, tricking users to install AppleJeus malware.

AppleJeus malware

AppleJeus malware, identified in 2018, enables the threat actors to have initial access to a network and steal crypto assets. The malware shows new evolution in the infection chain and abilities in this current campaign.

The new campaign

The campaign started when Lazarus Group registered the domain bloxholder[.]com. The website Lazarus Group built there is a clone of the legitimate website HaasOnline. HaasOnline is a Dutch company that developed HaasScript which is a crypto scripting language that allows users to create complex automated trading algorithms.

The cloned website distributed a Windows MSI installer that pretended to be an installer for the BloxHolder app. 

Volexity experts were not able to retrieve the final payload employed since October, but they noticed similarities in the DLL sideloading mechanism which is similar to the one used in the attacks relying on MSI installer.

Upon installation through the MSI infection chain, AppleJeus will create a scheduled task and drop additional files in the folder “%APPDATA%\Roaming\Bloxholder\”.

IOCs

Domains:

strainservice[.]com

bloxholder[.]com

rebelthumb[.]net

wirexpro[.]com

oilycargo[.]com

telloo[.]io

BloxHolder[.]com

Files:

%APPDATA%\Roaming\Bloxholder\CameraSettingsUIHost.exe

%APPDATA%\Roaming\Bloxholder\DUser.dll

%APPDATA%\Roaming\Bloxholder\18e190413af045db88dfbd29609eb877

BloxHolder_v1.2.5.msi

Scheduled Task:

%SYSDIR%\Tasks\Bloxholder*

Follow Us on: Twitter, InstagramFacebook to get the latest security news!

About the Author:

FirstHackersNews- Identifies Security

Leave A Comment

Subscribe to our newsletter to receive security tips everday!