Security researchers have discovered a new type of “Fileless Malware” distributed by the APT group Lazarus. According to a researcher from Labs , the hacking group is targeting MacOS users with malware.
The researcher said that hackers have targeted several apps by compromising Mac applications. The goal was to steal cryptocurrency.
Infection process
According to the researcher, the attackers infect an open-source trading application with the malware. Once infected, the malware serial number Mac and operating system information and transfers it to the attackers.
"The Lazarus group targeted cryptocurrency exchanges using malicious applications. The usual method for trojanising a Mac application is quite simple. Hackers place their backdoor and file in the resource directory of an open-source trading application and then exploit the post-install script to activate their backdoor," the researcher.

The researcher also discovered a trojanized version of the UnionCryptoTrader.dmg file . The campaign likely began in June 2019.
The Lazarus hacking group is now well-known, having been involved in many cyberattacks. The hackers often target cryptocurrency theft. In 2018, Kaspersky Lab had discovered a malicious operation by the group, known as AppleJeus. This operation also targeted cryptocurrency exchanges and applications.
Researchers had discovered that attackers infiltrated the network of an Asian exchange using trojanized software to steal cryptocurrencies .
According to Kaspersky, the breach occurred when an employee downloaded a cryptocurrency app from a malicious site. This resulted in the installation of the Fallchill, which gave hackers access and allowed them to steal data and cryptocurrencies.
