U.S. agencies and private researchers linked multiple cryptocurrency-focused malware campaigns to North Korea’s Lazarus Group/HIDDEN COBRA, including the AppleJeus family delivered through fake but functional trading and wallet applications for Windows and macOS. CISA reports said variants including Celas Trade Pro, JMT Trading, Kupay Wallet, and CoinGoTrade were distributed from spoofed or seemingly legitimate websites such as celasllc.com, jmttrading.org, and kupaywallet.com, often with GitHub-hosted installers. The applications presented benign trading interfaces while secretly installing updater, daemon, or backdoor components that collected host information, established persistence, and fetched encrypted second-stage payloads from attacker-controlled infrastructure.
The malware gave operators remote access to victim systems in cryptocurrency exchanges, financial services firms, and related organizations, with capabilities including command execution, file upload and transfer, reconnaissance, and payload staging. CISA tied the campaigns to Lazarus through infrastructure and code overlap with known implants such as FALLCHILL, HOPLIGHT/MANUSCRYPT, and the CrashReporter backdoor, while Proofpoint documented related Lazarus activity using phishing documents, JavaScript downloaders, malicious LNK and CHM files, and backdoored cryptocurrency apps to deploy PowerRatankba, a custom Gh0st RAT variant, and RatankbaPOS. Together, the reporting shows a sustained Lazarus effort to steal cryptocurrency and gain access to crypto-sector networks by masquerading malware as legitimate trading software.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
On April 15, 2021, CISA published a malware analysis report on the AppleJeus variant Kupay Wallet. The report described Lazarus-linked trojanized wallet software for Windows and macOS and its follow-on payload behavior.
On February 17, 2021, CISA published malware analysis reports covering the AppleJeus variants Celas Trade Pro, JMT Trading, and CoinGoTrade. The reports attributed the campaigns to the Lazarus Group and detailed trojanized cryptocurrency applications used to target the cryptocurrency sector.
CISA said the Lazarus-linked AppleJeus variant Ants2Whale was discovered in October 2020 as a trojanized cryptocurrency trading application distributed via ants2whale.com. The macOS malware targeted individuals and companies, including cryptocurrency exchanges and financial services firms.
CISA reported that the AppleJeus variant CoinGoTrade was discovered in October 2020 as a legitimate-looking cryptocurrency trading software and website used as a malware delivery lure. The campaign targeted cryptocurrency-sector individuals and companies.
The attacker-controlled cryptocurrency website esilet.com, later used to distribute the trojanized macOS installer Esilet.dmg in a Lazarus campaign, was registered on 2020-06-12. TeamT5 linked the infrastructure and the rewritten MovieRAT malware variant to Lazarus targeting cryptocurrency users.
CISA's report says the Lazarus-linked AppleJeus variant Dorusio was discovered in March 2020 as legitimate-looking cryptocurrency trading or wallet software distributed via dorusio.com. The campaign used Windows and macOS installers that deployed a benign-looking wallet alongside a malicious updater targeting cryptocurrency-sector individuals and organizations.
CISA said the Lazarus-linked AppleJeus variant Kupay Wallet was discovered in March 2020 as a legitimate-looking cryptocurrency trading software offering. The campaign used kupaywallet.com to distribute trojanized Windows and macOS applications.
The domain coingotrade.com, later used to market and distribute the CoinGoTrade malware, was registered through NameCheap on 2020-02-28. CISA linked the site to the Lazarus Group's AppleJeus activity.
The domain kupaywallet.com, later used to distribute the trojanized Kupay Wallet application, was created through NameCheap on 2020-02-21. CISA identified it as infrastructure for the Lazarus-linked AppleJeus campaign.
The command-and-control domain beastgoc.com went offline soon after public reporting on October 13, 2019, according to CISA. The domain had been used by the JMT Trading CrashReporter malware on Windows and macOS.
The CISA report states that soon after October 11, 2019, the malicious JMT Trading files hosted on GitHub were replaced with clean, non-malicious installers. This followed public exposure of the campaign.
Open-source reporting in August 2018 revealed a trojanized Celas Trade Pro cryptocurrency trading application on a victim's computer. The victim company was subsequently compromised with the North Korean FALLCHILL remote administration tool.
Lazarus used the IDN domain xn--electrm-s2a[.]org in an Electrum-themed phishing campaign that sent emails and distributed backdoored wallet software. Proofpoint dated the email activity to approximately November 18 to 21, 2017.
A Lazarus phishing campaign impersonating Bitcoin Gold used the IDN domain xn--bitcoingld-lcb[.]org, displayed as bitcoingöld[.]org, to distribute backdoored PyInstaller applications. Proofpoint said this campaign ran approximately November 10 to 16, 2017.
Proofpoint reported that financially motivated Lazarus Group campaigns targeting cryptocurrency users and organizations began on or around June 30, 2017. The activity used the new PowerRatankba malware cluster delivered through multiple infection vectors.
Researchers identified a Lazarus-linked campaign using a trojanized DeFi Wallet application to infect cryptocurrency and DeFi targets with a backdoor while installing a legitimate wallet app as cover. The report tied the malware and multi-stage C2 infrastructure to Lazarus with high confidence based on overlaps with CookieTime/LCPDot, Manuscrypt, and ThreatNeedle.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
teamt5.org
Open sourcesecurelist.com
Open sourceus-cert.cisa.gov
Open sourceus-cert.cisa.gov
Open sourceus-cert.cisa.gov
Open sourceus-cert.cisa.gov
Open sourceblogs.jpcert.or.jp
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.