What is the issue - Researchers from Kaspersky observed Lazarus threat group’s new operation that utilizes PowerShell to target Windows and MacOS systems.
Why it matters - Researchers noted that the threat group’s new operation is a part of the Operation AppleJeus and is ongoing since November 2018.
The big picture
The threat group’s ongoing operation targets the staff of cryptocurrency exchanges with malicious documents that would download and install either Windows or Mac malware.
Worth noting - Lazarus threat group uses various techniques to run its C&C servers such as purchasing new servers, using hacked servers, using old vulnerable servers etc.
According to server response headers, Lazarus threat group is running two different C&C servers.
“We’d therefore like to ask Windows and macOS users to be more cautious and not fall victim to Lazarus. If you’re part of the booming cryptocurrency or technological startup industry, exercise extra caution when dealing with new third parties or installing software on your systems,” researchers wrote in a blog.
Publisher