Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Strovemont Capital Claims Evaluated: Is Strovemont Capital Trading Platform Legit? Hidden Features, Trust Facts & Real User Results

April 20, 2026

BNB Chain Prepares Osaka/Mendel Upgrade to Improve Execution and Finality

April 20, 2026

Ethereum staking crosses 32% – Yet ETH still lacks ONE KEY driver

April 20, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Lazarus Group Targets MacOS Users Seeking Crypto Jobs
Lazarus Group Targets MacOS Users Seeking Crypto Jobs
Security and Privacy

Lazarus Group Targets MacOS Users Seeking Crypto Jobs

June 10, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Security researchers at SentinelOne have uncovered a variant of the Operation In(ter)ception campaign using lures for job vacancies at cryptocurrency exchange platform Crypto.com to infect macOS users with malware.

According to an advisory published on Monday, the new attacks would represent a further instance of a campaign spotted by ESET and Malwarebytes in August and attributed to North Korea–linked advanced persistent threat (APT) Lazarus Group.

The main difference would be that the original campaign targeted Coinbase instead of Crypto.com.

“While those campaigns distributed Windows malware, macOS malware has been discovered using a similar tactic,” reads the advisory.

“Decoy PDF documents advertising positions on crypto exchange platform Coinbase were discovered by our friends at ESET back in August 2022, with indications that the campaign dated back at least a year. Last week, SentinelOne observed variants of the malware using new lures for vacancies at Crypto.com.”

The security company said that, at the time of writing, it is not clear yet how the malware is being distributed. However, earlier reports suggested that threat actors targeted victims via private messaging on LinkedIn.

From a technical standpoint, SentinelOne said the first stage dropper is a Mach–O binary that is a similar template to the binary used in the Coinbase variant. The first stage then creates a new folder in the user’s library and drops a persistence agent.

The primary purpose of the second stage is to extract and execute the third–stage binary, which in turn acts as a downloader from a C2 server.

“The threat actors have made no effort to encrypt or obfuscate any of the binaries, possibly indicating short–term campaigns and/or little fear of detection by their targets,” reads the advisory.

See also  Crypto Companies In New York May No Longer Self-Certify "Coin Listings"

More generally, SentinelOne said Operation In(ter)ception appears to be extending the targets from users of crypto exchange platforms to their employees in “what may be a combined effort to conduct both espionage and cryptocurrency theft.”

A list of indicators of compromise (IoC) is available in the original text of the advisory. Its publication comes weeks after Cisco Talos unveiled new details regarding a Lazarus hacking campaign the group conducted against several energy providers between February and July 2022.

Source link

Crypto Group Jobs Lazarus macOS Seeking Targets users
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Patrick Witt Reveals White House Stepped In to Save Crypto Bill

April 19, 2026

Previewing Consensus’ Policy Summit: State of Crypto

April 19, 2026

Russia introduces bill to criminalize unregistered crypto services

April 19, 2026

$8.8 billion at risk! Can crypto avoid Monday shakeout if U.S. stocks crack?

April 19, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Ethereum whale initiates massive exodus from Binance

November 6, 2023

Hong Kong eyes stablecoin licensing regime to bolster crypto stability

July 17, 2024

The Regulatory Vacuum Just Sucked $4B Out of Binance and Coinbase

June 13, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Strovemont Capital Claims Evaluated: Is Strovemont Capital Trading Platform Legit? Hidden Features, Trust Facts & Real User Results

April 20, 2026

BNB Chain Prepares Osaka/Mendel Upgrade to Improve Execution and Finality

April 20, 2026

Ethereum staking crosses 32% – Yet ETH still lacks ONE KEY driver

April 20, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$74,496.00-1.36%
  • ethereumEthereum(ETH)$2,279.19-2.54%
  • tetherTether(USDT)$1.000.01%
  • rippleXRP(XRP)$1.41-1.39%
  • binancecoinBNB(BNB)$621.04-0.55%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$84.10-1.57%
  • tronTRON(TRX)$0.3312901.07%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.040.00%
  • dogecoinDogecoin(DOGE)$0.093861-0.73%