DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Tech News

Lazarus threat group’s new campaign targets Windows and MacOS systems

DigitalCIO Bureau by DigitalCIO Bureau
March 28, 2019
in Tech News
0
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Source: Cyware | By Ryan Stewart

• Lazarus threat group’s new operation utilizes PowerShell to target Windows and MacOS systems.
• This operation is a part of the Operation AppleJeus and is ongoing since November 2018.

What is the issue – Researchers from Kaspersky observed Lazarus threat group’s new operation that utilizes PowerShell to target Windows and MacOS systems.

Why it matters – Researchers noted that the threat group’s new operation is a part of the Operation AppleJeus and is ongoing since November 2018.

The big picture
The threat group’s ongoing operation targets the staff of cryptocurrency exchanges with malicious documents that would download and install either Windows or Mac malware.

• The threat group’s custom PowerShell script communicates with the malicious C&C server and executes commands.
• Once the malware establishes a connection with the C&C server, it can upload/download files, gather host information, execute system shell command, and set sleep time.
• The malware is also capable of checking malware status, displaying current malware configuration, updating malware configuration, and exiting the malware.

Worth noting – Lazarus threat group uses various techniques to run its C&C servers such as purchasing new servers, using hacked servers, using old vulnerable servers etc.

According to server response headers, Lazarus threat group is running two different C&C servers.

• One C&C server is an old vulnerable instance of Internet Information Services (IIS) 6.0 on Microsoft Windows Server 2003.
• The other C&C server is a purchased instance from a hosting company and is currently used to host macOS and Windows payloads.
• The geography of the servers varies from China to the European Union.

“We’d therefore like to ask Windows and macOS users to be more cautious and not fall victim to Lazarus. If you’re part of the booming cryptocurrency or technological startup industry, exercise extra caution when dealing with new third parties or installing software on your systems,” researchers wrote in a blog.

Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

Nvidia working on customized version of its H20 chip for China

by DigitalCIO Bureau
May 10, 2025
0
Nvidia working on customized version of its H20 chip for China

Nvidia intends to release a modified version of its H20 artificial intelligence chip for China within two months, reported Reuters citing sources. This will allow Nvidia to circumvent...

Read moreDetails

Wipro names Sandeep Dhar as Global Head of its GCC Practice

by DigitalCIO Bureau
May 9, 2025
0
Wipro names Sandeep Dhar as Global Head of its GCC Practice

Wipro Limited has announced the appointment of Sandeep Dhar as Global Head of its Global Capability Center (GCC) practice. Sandeep brings over 30 years of experience in the...

Read moreDetails

Responsive Report: AI Agents Drive Revenue Growth For Global B2B Enterprises

by DigitalCIO Bureau
May 9, 2025
0
CISOs Need to Champion AI TRiSM to Improve AI Results

Responsive, the global leader in AI-powered Strategic Response Management (SRM) software, in partnership with the Association of Proposal Management Professionals (APMP), today released its 2025 State of Strategic...

Read moreDetails

HCLTech Join Hands With CareAR And ServiceNow To Launch AR- Based IT Infrastructure Solution

by DigitalCIO Bureau
May 9, 2025
0
HCLTech Join Hands With CareAR And ServiceNow To Launch AR- Based IT Infrastructure Solution

HCLTech has launched an augmented reality (AR)-based infrastructure management solution in collaboration with CareAR and ServiceNow to enhance IT operations with augmented intelligence, real-time remote assistance and automation-driven workflows. HCLTech is...

Read moreDetails

Japanese users targeted in new phishing attack

by DigitalCIO Bureau
May 9, 2025
0
Phishing emails using Adobe InDesign on the rise, Barracuda Threat Spotlight reveals

Cybersecurity firm Proofpoint points to a new phishing attack called CoGUI that is primarily targeting Japanese companies and has a financial motive. Japanese authorities have recently warned of...

Read moreDetails
Next Post

Accenture has good news for the whole of IT

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Veeam Launches Cyber Secure Program to Help Enterprises Protect and Recover from Ransomware Attacks

Veeam Brings Data Resilience To Over 21mln Microsoft 365 Users

August 1, 2024

Infosys, Microsoft to offer solutions for digital shift

August 29, 2019
TSMC, Bosch, Infineon And NXP To Bring Advanced Semiconductor Manufacturing to Europe

Worldwide Semiconductor Revenue to Grow 17% in 2024

December 4, 2023

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Dell Technologies Digital Transformation Dynatrace E-books Fortinet Gartner GenAI Generative AI Google Cloud Honeywell IBM Infographics Internet of Things (IoT) Kaspersky Kyndryl Microsoft Netskope Nutanix Palo Alto Networks Panel Discussion Qlik Salesforce Schneider Electric ServiceNow Sophos Tenable Veeam Veeam Software Vertiv Webinars Whitepaper

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?