Lazarus gang hackers used a signed malicious software for macOS to spoof Coinbase and deceive fintech workers…

Continue reading
North Korean hackers from the Lazarus gang have been impersonating Coinbase and luring personnel in the financial technology sector using a signed malicious application for macOS.
Even though it's not surprising that they're going after people who work at Web3 companies, we don't know much about this particular social engineering campaign yet.
In a recent operation, Lazarus hackers disguised malware as a PDF file with information on a position at Coinbase. In the past, they have exploited bogus job postings.
The phony paper was titled "Coinbase online careers 2022 07." When executed, it displays the aforementioned decoy PDF and loads a malicious DLL that enables the threat actor to transmit orders to the affected device.
Researchers from the antivirus firm ESET discovered that the hackers also had malware prepared for macOS systems. They reported that the malicious program is compiled for Macs with both Intel and Apple hardware, indicating that both older and newer models were affected.
In a Twitter thread, they observe that the virus dumps three files: the bundle FinderFontsUpdater.app, the downloader safarifontagent, and a dummy PDF titled "Coinbase online careers 2022 07" (same as the Windows malware)
Last year, a similar effort targeting macOS users was linked to Lazarus. The threat actor relied on the same social engineering tactic involving a phony job offer, but used a different PDF.
ESET correlated the current macOS virus with Operation In(ter)ception, a Lazarus campaign that similarly targeted prominent aerospace and military institutions.
The macOS virus was signed on July 21 (according to the timestamp value) using a certificate granted in February to a developer with the name Shankey Nohria and the team identification 264HFWQL63.
On August 12, Apple had not withdrawn the certificate. The rogue application was not, however, notarized - a procedure Apple uses to automatically examine applications for dangerous components.
Compared to the previous macOS malware attributed to the Lazarus hacking organization, ESET researchers discovered that the downloader component communicates to a distinct command and control (C2) server, which was inactive at the time of investigation.
Historically, North Korean hacking groups have been tied to cryptocurrency breaches and phishing efforts that use false employment offers to infect targets of interest.

Backdoor.Daxin, the kernel-mode rootkit Symantec once called the most advanced tool ever tied to a China-linked espionage actor, has been found running again