North Korea-based notorious Lazarus hacking group is back in action, targeting Apple Mac users with fake job emails that contain malicious files.
Researchers at cyber-security firm ESET posted a screenshot on Twitter that showed fake job listings from leading crypto exchange Coinbase by Lazarus, famous for spreading the WannaCry ransomware globally in 2017.
The fake job listing was for an engineering manager, product security, at Coinbase.
"A signed Mac executable disguised as a job description for Coinbase was uploaded to VirusTotal from Brazil. This is an instance of Operation by Lazarus for Mac," the ESET researchers posted in a tweet.
The fake job emails have an attachment containing malicious files that can compromise both Intel and Apple chip-powered Mac computers.
"Malware is compiled for both Intel and Apple Silicon. It drops three files: a decoy PDF document, a bundle and a downloader," warned researchers.
The Mac malware campaign is new and not part of previous Lazarus campaigns.
This time, "the bundle is signed July 21 (according to the timestamp) using a certificate issued in February 2022 to a developer named Shankey Nohria. The application is not notarised and Apple has revoked the certificate on August 12," the researchers noted.
Last month, cyber-security researchers linked Lazarus with stealing $100 million worth digital tokens from Harmony, the crypto startup behind Horizon Blockchain Bridge.
The Lazarus Group has perpetrated several large cryptocurrency thefts totalling over $2 billion, and has recently turned its attention to Decentralised Finance (DeFi) services such as cross-chain bridges, according to London-based blockchain analysis provider Elliptic.
The same group is believed to be behind the $540 million hack of Ronin Bridge.
--IANS
na/dpb
(Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)
You’ve hit your limit of {{free_limit}} free articles this month.
Subscribe now for unlimited access.
Already subscribed? Log in
Subscribe to read the full story →
Quarterly Starter
₹900
3 Months
₹300/Month
Smart Essential
₹2,700
1 Year
₹225/Month
Super Saver
₹3,900
2 Years
₹162/Month
Renews automatically, cancel anytime
Here’s what’s included in our digital subscription plans
Access to Exclusive Premium Stories Online
Over 30 behind the paywall stories daily, handpicked by our editors for subscribers


Complimentary Access to The New York Times
News, Games, Cooking, Audio, Wirecutter & The Athletic
Business Standard Epaper
Digital replica of our daily newspaper — with options to read, save, and share


Curated Newsletters
Insights on markets, finance, politics, tech, and more delivered to your inbox
Market Analysis & Investment Insights
In-depth market analysis & insights with access to The Smart Investor


Archives
Repository of articles and publications dating back to 1997
Ad-free Reading
Uninterrupted reading experience with no advertisements


Seamless Access Across All Devices
Access Business Standard across devices — mobile, tablet, or PC, via web or app