Security News > 2022 > September > North Korea's Lazarus Hackers Targeting macOS Users Interested in Crypto Jobs

The infamous Lazarus Group has continued its pattern of leveraging unsolicited job opportunities to deploy malware targeting Apple's macOS operating system.
In the latest variant of the campaign observed by cybersecurity company SentinelOne last week, decoy documents advertising positions for the Singapore-based cryptocurrency exchange firm Crypto.com.
The latest disclosure builds on previous findings from Slovak cybersecurity firm ESET in August, which delved into a similar phony job posting for the Coinbase cryptocurrency exchange platform.
Both these fake job advertisements are just the latest in a series of attacks dubbed Operation In(ter)ception, which, in turn, is a constituent of a broader campaign tracked under the name Operation Dream Job.
The intrusions commence with the deployment of a Mach-O binary, a dropper that launches the decoy PDF document containing the job listings at Crypto.com, while, in the background, it deletes the Terminal's saved state.
These attacks are not isolated, for the Lazarus Group has a history of carrying out cyber-assaults on blockchain and cryptocurrency platforms as a sanctions-evading mechanism, enabling the adversaries to gain unauthorized access to enterprise networks and steal digital funds.
News URL
https://thehackernews.com/2022/09/north-koreas-lazarus-hackers-targeting.html
Related news
- US govt says North Korea stole over $659 million in crypto last year (source)
- Crypto klepto North Korea stole $659M over just 5 heists last year (source)
- North Korea targets crypto developers via NPM supply chain attack (source)
- Hackers Exploit Aviatrix Controller Vulnerability to Deploy Backdoors and Crypto Miners (source)
- Microsoft: macOS bug lets hackers install malicious kernel drivers (source)
- North Korean Hackers Deploy FERRET Malware via Fake Job Interviews on macOS (source)
- I'm a security expert, and I almost fell for a North Korea-style deepfake job applicant …Twice (source)
- zkLend loses $9.5M in crypto heist, asks hacker to return 90% (source)
- Microsoft spots XCSSET macOS malware variant used for crypto theft (source)
- Hackers pose as employers to steal crypto, login credentials (source)