Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Here is why Strategy's dividend-paying crypto stock is crashing to near-historic lows

June 16, 2026

HashKey Chain Partners Morpho to Blend Compliance and DeFi for Institutional CeDeFi and RWA Lending

June 16, 2026

Kraken Brings Regulated Perpetual Futures Onshore to US Users

June 16, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Lazarus Group Targets MacOS Users Seeking Crypto Jobs
Lazarus Group Targets MacOS Users Seeking Crypto Jobs
Security

Lazarus Group Targets MacOS Users Seeking Crypto Jobs

October 21, 2023No Comments2 Mins Read

Security researchers at SentinelOne have uncovered a variant of the Operation In(ter)ception campaign using lures for job vacancies at cryptocurrency exchange platform Crypto.com to infect macOS users with malware.

According to an advisory published on Monday, the new attacks would represent a further instance of a campaign spotted by ESET and Malwarebytes in August and attributed to North Korea–linked advanced persistent threat (APT) Lazarus Group.

The main difference would be that the original campaign targeted Coinbase instead of Crypto.com.

“While those campaigns distributed Windows malware, macOS malware has been discovered using a similar tactic,” reads the advisory.

“Decoy PDF documents advertising positions on crypto exchange platform Coinbase were discovered by our friends at ESET back in August 2022, with indications that the campaign dated back at least a year. Last week, SentinelOne observed variants of the malware using new lures for vacancies at Crypto.com.”

The security company said that, at the time of writing, it is not clear yet how the malware is being distributed. However, earlier reports suggested that threat actors targeted victims via private messaging on LinkedIn.

From a technical standpoint, SentinelOne said the first stage dropper is a Mach–O binary that is a similar template to the binary used in the Coinbase variant. The first stage then creates a new folder in the user’s library and drops a persistence agent.

The primary purpose of the second stage is to extract and execute the third–stage binary, which in turn acts as a downloader from a C2 server.

“The threat actors have made no effort to encrypt or obfuscate any of the binaries, possibly indicating short–term campaigns and/or little fear of detection by their targets,” reads the advisory.

See also  88 people charged over 12 crypto wrench attacks in France

More generally, SentinelOne said Operation In(ter)ception appears to be extending the targets from users of crypto exchange platforms to their employees in “what may be a combined effort to conduct both espionage and cryptocurrency theft.”

A list of indicators of compromise (IoC) is available in the original text of the advisory. Its publication comes weeks after Cisco Talos unveiled new details regarding a Lazarus hacking campaign the group conducted against several energy providers between February and July 2022.

Source link

Crypto Group Jobs Lazarus macOS Seeking Targets users

Related Posts

Here is why Strategy's dividend-paying crypto stock is crashing to near-historic lows

June 16, 2026

Kraken Brings Regulated Perpetual Futures Onshore to US Users

June 16, 2026

India’s NHRC Raises Alarm Over Digital Arrest Scams

June 16, 2026

Bitcoin.com Wallet Adds FixedFloat as a Swap Provider for Flexible Crypto Swaps

June 16, 2026
Top Posts

G121ICE-L02 new For 12.1 inch 1280*800 LCD Screen Display

March 13, 2026

State of Cybersecurity Report 2022

October 30, 2023

As Wall Street moves on-chain, DeFi faces a $330 billion trust test it can’t dodge

April 5, 2026

Type above and press Enter to search. Press Esc to cancel.