Scam Alert

Lazarus Group With New Crypto Scam Plan Through App Spreading Malware

Volexity, a cybersecurity firm located in Washington, D.C., has linked Lazarus, a North Korean hacker organization already sanctioned by the US government, to a threat involving the use of a cryptocurrency site to infect computers and steal information and crypto from third parties.

According to a blog post published on December 1, Lazarus registered a domain named “bloxholder.com” in June, which would eventually be formed as a business offering services of automatic crypto trading.

(We recommend that you do not visit the website to avoid property theft)

Using this site as a front, Lazarus prompted users to download an app that served as a payload for the Applejeus malware, which was designed to steal private keys and other data from the users’ systems.

Lazarus has previously employed the same strategy. This new scheme, on the other hand, employs a technique that allows the application to confuse and slow down malware detection tasks.

The Lazarus hacker gang was delivering AppleJeus malware using maliciously. MS Office documents labeled OKX, Binance & Huobi VIP fee comparision.xls instead of an MSI installer, according to Volexity researchers. This change was noted in October 2022.

The infected document contains a two-part macro. The first decoded a base64 blob that included a second OLE object with a second macro.

Fraudulent website interface

Furthermore, the initial document contains a number of variables encoded with base 64 to allow the virus to be distributed in the targeted system. The hackers also utilized OpenDrive to distribute the final stage payload.

However, researchers have been unable to recover the final payload sent since October. They discovered parallels between the DLL Side-loading process and the assaults employing the MSI installation.

DISCLAIMER: The Information on this website is provided as general market commentary and does not constitute investment advice. We encourage you to do your own research before investing.

Join us to keep track of news: https://linktr.ee/coincu

Website: coincu.com

Harold

Coincu News

Harold

With a passion for untangling the complexities of the financial world, I've spent over four years in financial journalism, covering everything from traditional equities to the cutting edge of venture capital. "The financial markets are a fascinating puzzle," I often say, "and I love helping people make sense of them." That's what drives me to bring clear and insightful financial journalism to the readers of Coincu.

Recent Posts

Invesco Galaxy Ethereum ETF Delayed By SEC Until July 5

The United States Securities and Exchange Commission (SEC) has extended its decision deadline for the…

4 hours ago

LayerZero Sybil Detection Report Is Being Conducted With Chaos Labs And Nansen

LayerZero Labs collaborates with Chaos Labs and Nansen to conduct a LayerZero sybil detection report…

4 hours ago

MicroStrategy Bitcoin Holding Now Surpasses Every Country With 214,400 BTC

MicroStrategy Bitcoin holdings are now more than any country, with 214,400 BTC worth $13.6 billion.

14 hours ago

Bitcoin Seoul 2024: Uniting Visionaries, Innovators, and Advocates for a Crypto Revolution

The highly anticipated Bitcoin Seoul 2024 conference is gearing up to be a revolutionary event…

15 hours ago

Non-Fungible Conference 2024: Exploring the Future of Digital Culture in Lisbon’s Vibrant Hub

As an experimental festival, Non-Fungible Conference aims to revolutionize event frameworks, offering attendees a glimpse…

15 hours ago

Blockchain Week Rome 2024: Uniting Global Crypto Communities in the Heart of Italy

Blockchain Week Rome 2024 is set to unite the Italian and international crypto communities in…

15 hours ago

This website uses cookies.