That Coinbase job offer could actually be North Korean hackers


Experts have warned that the dangerous Lazarus group is now targeting Web3 developers on Mac devices.
The North Korean state-sponsored threat actor recently went after blockchain developers with fake lucrative job offers that turned out to be nothing more than infostealers and malware (opens in new tab).
While these attacks were limited to Windows users at first, cybersecurity researchers from ESET have now discovered they are expanding into Apple territory, too.
Intel and Apple chips attacked
The campaign is pretty much the same for both platforms. The group would impersonate Coinbase, one of the largest and most popular cryptocurrency exchanges in the world, and reach out to blockchain developers via LinkedIn and other platforms with a job offer. After a little back-and-forth, and a few rounds of “interviews”, the attacker would serve the victim what seems to be a .pdf file with the job position’s details.
The file’s name is Coinbase_online_careers_2022_07, and while it looks like a .pdf (icon and all), it is actually a malicious DLL that allows Lazarus to send commands to the infected endpoint. The file is compiled for Macs with both Intel and Apple processors, the researchers further discovered, suggesting that the group is after both older, and newer device models.
Detailing the attack via Twitter, the researchers said the malware drops three files: the bundle FinderFontsUpdater.app, the downloader safarifontagent, and a decoy PDF called “Coinbase_online_careers_2022_07.pdf”.
Lazarus Group is no stranger to fake job offer attacks, and it’s conducted these attacks in the past with much success. In fact, one of the largest cryptocurrency heists in history, the $600+ million-heavy attack on the Ronin bridge, was done in that exact manner.
After reaching out to a software engineer and luring him into downloading the fake .pdf file, the attackers from Lazarus found their way into the system, obtained the necessary credentials, and siphoned out millions in cryptocurrency tokens.
In this case, however, the malware was signed on July 21, with a certificate issued to a developer going by the name Shankey Nohria. The team identifier was 264HFWQH63. While the certificate had not been revoked on August 12 when it was checked, BleepingComputer reports, the researchers did find that Apple didn’t scan it for malicious components.
Via: BleepingComputer (opens in new tab)
Audio player loading… Experts have warned that the dangerous Lazarus group is now targeting Web3 developers on Mac devices. The North Korean state-sponsored threat actor recently went after blockchain developers with fake lucrative job offers that turned out to be nothing more than infostealers and malware (opens in new tab). …
Recent Posts
- Xiaomi 15 Ultra is a small update with a big periscope lens
- Amazon’s upgraded Alexa+ will enable Fire TV devices to skip to a particular scene in a movie just by describing it
- Prime Video puts a Supernatural spin on The Boys season 5 cast as Jared Padalecki and Misha Collins sign on to the popular show in mystery roles
- The New York City Subway Is Using Google Pixels to Listen for Track Defects
- Elon Musk and DOGE are using Slack, Salesforce CEO Benioff says
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010