# Lazarus deploys new AppleJeus variant via JMTTrading

Published: 2026-08-02 · Severity: high · Sectors: financial-services
Canonical: https://vorant.io/reports/5b1ec8c7-92f0-5398-aee6-5fe16fb05d58/lazarus-deploys-new-applejeus-variant-via-jmttrading

> Lazarus Group used a fake crypto-trading firm, JMT Trading, to distribute a new macOS AppleJeus backdoor with full remote command execution.

Researcher Patrick Wardle analyzed a new macOS malware sample, distributed via a trojanized cryptocurrency trading application called "JMTTrader," hosted on a fake company website (jmttrading.org) and a GitHub release page. The infection chain closely mirrors Kaspersky's previously documented "Operation AppleJeus" campaign, in which Lazarus Group created a fake company ("Celas Trade Pro") to trick cryptocurrency exchange employees into installing malicious trading software. The JMTTrader.pkg installer drops a launch daemon (org.jmttrading.plist) and a persistent Mach-O binary (CrashReporter) that requires a specific command-line argument to execute — a known Lazarus anti-analysis technique.

Once running, the CrashReporter binary contacts a hardcoded C2 (beastgoc.com, resolving to 185.228.83.32) over HTTPS, sending XOR-encrypted beacons containing a random token, version, and PID. The malware supports commands including exit, file upload (up), and arbitrary shell command execution via popen, giving an attacker full remote control of infected macOS hosts. While architecturally and functionally distinct from the previously analyzed Qt-based Lazarus backdoor (different commands, no cross-platform code, no system-recon functions), multiple design similarities — the fake-company lure, unsigned/ad-hoc-signed installer package, launch daemon persistence pattern, and command-line-argument gating logic — strongly tie this sample to the same actor.

At time of analysis the sample was undetected by all VirusTotal engines, though behavior-based tools (BlockBlock, LuLu, Netiquette) readily flagged the persistence and C2 activity. The malware appears targeted at employees of cryptocurrency exchanges rather than the general public, consistent with Lazarus's financially-motivated targeting of crypto infrastructure.

## Mentioned in this report

- Threat actors: Lazarus Group
- Malware: OSX.AppleJeus (JMTTrader variant / CrashReporter)
- Campaigns: Operation AppleJeus

Source reporting: https://objective-see.org/blog/blog_0x49.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5b1ec8c7-92f0-5398-aee6-5fe16fb05d58/lazarus-deploys-new-applejeus-variant-via-jmttrading.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
