VORANT. Threat Intelligence Sign in Get the full feed

Objective-See dissects Lazarus NukeSped macOS backdoor

medium threat financial-servicestechnology

Objective-See's deep dive into a CISA-flagged Lazarus campaign shows a trojanized Electron crypto app dropping the NukeSped/Manuscrypt macOS backdoor.

This post expands on an April CISA advisory attributing a campaign against blockchain and cryptocurrency firms to North Korea's Lazarus Group (APT38), analyzing a specific macOS sample distributed as a trojanized Electron application named "Esilet." The unsigned app, delivered via a disk image, ships with an unpacked asar archive containing JavaScript that silently checks a hardcoded update URL, downloads a second-stage payload, and executes it — a pattern CISA has dubbed TraderTraitor.

The downloaded second-stage binary is a NukeSped (aka Manuscrypt) backdoor. Static and dynamic analysis show it persists via a LaunchAgent plist, beacons to hardcoded C2 domains over HTTP using libcurl, and supports a tasking switch-statement allowing remote system surveying (sw_vers, network config), arbitrary shell command execution via /bin/bash, and file read/write/exfiltration capabilities. Observed C2 infrastructure (vinoymas.ch, sche-eg.org, infodigitalnew.com) appeared offline at time of analysis.

The author confirms that Objective-See's free tools (KnockKnock, BlockBlock, LuLu) detect the malware's persistence and C2 network activity, framing the piece as both threat research and a validation of heuristic-based detection against a known nation-state toolset targeting the cryptocurrency sector.

Mentioned in this report

Threat actors Lazarus Group
Malware EsiletNukeSped
Campaigns TraderTraitor

Source reporting: https://objective-see.org/blog/blog_0x6E.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free