OSX.AppleJeus.C is a macOS trojan attributed to the Lazarus Group and associated with the AppleJeus cryptocurrency-targeting campaign. It was distributed via a fake cryptocurrency trading application, UnionCryptoTrader, delivered from unioncrypto.vip as an unsigned installer package (including UnionCryptoTrader.dmg / UnionCryptoTrader.pkg). The malware targets employees or administrators of cryptocurrency exchanges through social engineering.
On installation, it prompts for root credentials and establishes persistence by installing a launch daemon at /Library/LaunchDaemons/vip.unioncrypto.plist and a hidden updater binary at /Library/UnionCrypto/unioncryptoupdater, which runs with root privileges. The implant collects basic host information including macOS version and serial number, then communicates with its C2 at https://unioncrypto.vip/update using libcurl. Reported protocol details include use of a hardcoded value "12GWAPCT1F0I1S14" during C2 communication.
A notable capability is delivery and execution of second-stage payloads directly from memory. The malware downloads encrypted payloads, described as base64-encoded and AES-encrypted/AES-CBC blobs, decrypts them, and attempts in-memory Mach-O execution using macOS APIs NSCreateObjectFileImageFromMemory and NSLinkModule. If in-memory loading fails, it falls back to writing the payload to /tmp/updater and executing it from disk. If no payload is returned, it sleeps for 10 minutes before beaconing again. This fileless execution approach is rare on macOS and increases stealth and forensic difficulty.
High-confidence artifacts and indicators mentioned in the content include MD5 6588d262529dc372c400bef8478c2eec, the persistence files /Library/LaunchDaemons/vip.unioncrypto.plist and /Library/UnionCrypto/unioncryptoupdater, the process /Library/UnionCrypto/unioncryptoupdater, and network connections to unioncrypto.vip. The campaign is described as consistent with Lazarus Group tradecraft and prior AppleJeus operations focused on cryptocurrency organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
OSX.AppleJeus.C is a macOS loader/backdoor attributed to the Lazarus Group. It achieves persistence via a launch daemon, beacons to a hardcoded C2 server, and downloads 2nd-stage payloads which it executes directly from memory (fileless execution). The loader uses AES encryption (key derived from system info) and base64 encoding for payload delivery, complicating detection and forensics. The malware is notable for its use of open-source in-memory loading code and is designed for stealth and anti-forensics.
A macOS backdoor/loader attributed to Lazarus Group, delivered via a trojanized cryptocurrency trading application. It achieves persistence via a launch daemon, collects system information, and beacons to a C2 server. It can download and execute additional payloads directly in memory, increasing stealth and complicating detection and forensics.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.