The North Korea-backed Lazarus APT group was found targeting job seekers with a fake job posting that attemptedto spread malware capable of executing on Apple Macs with Intel and M1 chipsets.
Slovak cybersecurity firm ESET linked the attack to a campaign dubbed “Operation In(ter)ception” that was first disclosed in June 2020 and involved using social engineering tactics to trick employees working in the aerospace and military sectors into opening decoy job offer documents.
In the latest attack, a job description for the Coinbase cryptocurrency exchange platform was used as a launchpad to drop a signed Mach-O executable.
The company tweeted that the malware is compiled for both Intel and Apple Silicon. It drops three files: a decoy PDF document ‘Coinbase_online_careers_2022_07.pdf’, a bundle ‘FinderFontsUpdater.app,’ and a downloader ‘safarifontagent.’
The decoy file, while sporting the .PDF extension, is actually a Mach-O executable that functions as a dropper to launch FinderFontsUpdater, which, in turn, executes safarifontsagent, a downloader designed to retrieve next-stage payloads from a remote server.
The malware is similar to a sample discovered by ESET in May, which also included a signed executable disguised as a job description, was compiled for both Apple and Intel, and dropped a PDF decoy.
However, the new malware was signed on July 21 using a certificate issued in February 2022 to a developer named Shankey Nohria. Apple has since moved to revoke the certificate on August 12.
Lazarus is known for targeting academics, journalists and professionals in various industries. A previous campaign identified in January also targeted job-seeking engineers by using fake employment opportunities at them in a spear-phishing campaign.














Comments