Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dubbed Operation In(ter)ception, the recent campaign drops a signed Mac executable disguised as a job description for Coinbase... “Malware is compiled for both Intel and Apple Silicon... It drops three files: a decoy PDF document Coinbase_online_careers_2022_07.pdf, a bundle http[://]FinderFontsUpdater[.]app and a downloader safarifontagent.”
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Lazarus-linked macOS malware operation using a signed fat binary disguised with a Coinbase job-vacancy lure. It drops decoy and staged components, establishes persistence via a LaunchAgent, executes secondary binaries, profiles the victim host, and contacts a C2 at concrecapital.com to download an additional payload.
A Lazarus-linked macOS malware campaign using a fake Coinbase job posting as lure material. The signed executable targets both Intel and Apple Silicon Macs, drops a decoy PDF plus additional components including a downloader, and communicates with separate C2 infrastructure. A companion Windows variant is also mentioned.
A targeted, custom multistage malware set used in a 2019 espionage operation: a Stage 1 downloader (executed via rundll32 or custom loaders) that fetches and memory-loads a Stage 2 modular C++ backdoor DLL for command execution, host profiling, module loading, and configuration changes; supported by LOLBins (WMIC/XSL, certutil, regsvr32/rundll32) and Dropbox CLI-based exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.