# Objective-See dissects Lazarus NukeSped macOS backdoor

Published: 2022-05-09 · Severity: medium · Sectors: financial-services, technology
Canonical: https://vorant.io/reports/bed75064-a009-543e-83bc-6a0486c67355/objective-see-dissects-lazarus-nukesped-macos-backdoor

> Objective-See's deep dive into a CISA-flagged Lazarus campaign shows a trojanized Electron crypto app dropping the NukeSped/Manuscrypt macOS backdoor.

This post expands on an April CISA advisory attributing a campaign against blockchain and cryptocurrency firms to North Korea's Lazarus Group (APT38), analyzing a specific macOS sample distributed as a trojanized Electron application named "Esilet." The unsigned app, delivered via a disk image, ships with an unpacked asar archive containing JavaScript that silently checks a hardcoded update URL, downloads a second-stage payload, and executes it — a pattern CISA has dubbed TraderTraitor.

The downloaded second-stage binary is a NukeSped (aka Manuscrypt) backdoor. Static and dynamic analysis show it persists via a LaunchAgent plist, beacons to hardcoded C2 domains over HTTP using libcurl, and supports a tasking switch-statement allowing remote system surveying (sw_vers, network config), arbitrary shell command execution via /bin/bash, and file read/write/exfiltration capabilities. Observed C2 infrastructure (vinoymas.ch, sche-eg.org, infodigitalnew.com) appeared offline at time of analysis.

The author confirms that Objective-See's free tools (KnockKnock, BlockBlock, LuLu) detect the malware's persistence and C2 network activity, framing the piece as both threat research and a validation of heuristic-based detection against a known nation-state toolset targeting the cryptocurrency sector.

## Mentioned in this report

- Threat actors: Lazarus Group
- Malware: Esilet, NukeSped
- Campaigns: TraderTraitor

Source reporting: https://objective-see.org/blog/blog_0x6E.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/bed75064-a009-543e-83bc-6a0486c67355/objective-see-dissects-lazarus-nukesped-macos-backdoor.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
