The notorious Lazarus hacking group is now using fake job offers on “Crypto.com,” targeting developers and artists in the cryptocurrency space, to steal digital assets and cryptocurrencies.
See also: Lazarus Group targets US energy providers

Crypto.com is one of the world's leading platforms . The company rose to prominence in 2021 when it purchased and renamed the Los Angeles Staples Center "Crypto.com Arena" and launched a series of television commercials promoting the service.
The Lazarus hacking group has been conducting a campaign called “Operation In(ter)ception” since 2020, targeting individuals working in the cryptocurrency industry.
Its goal is to trick its victims into opening malicious files that infect systems with malware that can be used to breach the internal networks of crypto companies to steal large amounts of cryptocurrencies, NFTs , or for espionage.
In August 2022, Lazarus was discovered targeting IT workers with malicious job offers impersonating Coinbase and targeting users with Windows malware or macOS malware.
In a new report by Sentinel One, hackers have now turned to mimicking Crypto.com in their phishing attacks using the same macOS seen in previous campaigns.
See also: Cryptocurrency platform deBridge Finance targeted by Lazarus
Lazarus typically approaches targets through LinkedIn, sending them a direct message to inform them of a lucrative job opening at a large company.

As in previous macOS campaigns, the hackers sent a macOS binary presented as a PDF containing a 26-page PDF file named “Crypto.com_Job_Opportunities_2022_confidential.pdf” containing alleged job vacancies at Crypto.com.
In the background, the Mach-O binary creates a folder (“WifiPreference”) in the user’s Library directory and drops the second and third stage files.
The second stage is “WifiAnalyticsServ.app” and its primary purpose is to extract and execute the third stage binary, which in turn acts as a downloader from a C2 server.
Security researchers were unable to retrieve the final payload for analysis because C2 was offline at the time of the investigation.
However, they observed features that indicate a short-lived operation, which is typical of "Operation In(ter)ception" campaigns.
Binaries are signed with an ad hoc signature so they can pass Apple Gatekeeper checks and run as trusted software.
See also: USA: Lazarus group uses malicious cryptocurrency apps
Most likely, Lazarus will soon switch to impersonating a different company, while keeping the rest of the attack elements largely unchanged.
If you work for a crypto company, be wary of unsolicited job offers on LinkedIn, as a moment of inattention is enough to act as a Trojan horse for your employer.
