Skip to main content

Boteraser | Website and Server Security Solutions

Tiop

Malware

⚠️ Overview

Tiop is a macOS backdoor trojan first publicly documented by Kaspersky in 2018 as part of the AppleJeus campaign, attributed to the North Korean Lazarus Group and its BlueNoroff sub-group (also tracked as APT38). It is classified as a remote access trojan (RAT) and a downloader, specifically designed to infiltrate cryptocurrency exchange operators and financial institutions.

🔧 Technical Capabilities

Tiop propagates through trojanized cryptocurrency trading applications distributed via malicious websites and emails that mimic legitimate financial software (e.g., "CoinStash" or "Tiop.app"). Once executed, it collects system information—including OS version, computer name, and running processes—and communicates with its command-and-control (C2) server over HTTPS (MITRE ATT&CK T1071.001). It can download and execute additional payloads, such as keyloggers and credential stealers, by fetching secondary stages from the C2. Persistence is achieved via a LaunchAgent plist file (T1543.001) that ensures Tiop restarts upon system reboot. For defense evasion, it uses process injection (T1055) into legitimate macOS processes and obfuscates its binary with custom encryption or compression algorithms.

📜 History & Notable Incidents

Tiop first appeared in 2018 as a core component of the AppleJeus campaign, which targeted multiple cryptocurrency exchanges in South Korea and Japan. A high-profile incident involved a South Korean exchange that lost an estimated $80 million in cryptocurrency, where Tiop was used as the initial infection vector to drop additional malware like the "Shlayer" adware variant. No specific CVEs are directly associated with Tiop, as it exploits social engineering rather than unpatched vulnerabilities. Law enforcement actions have not resulted in arrests, but the U.S. Department of the Treasury sanctioned the Lazarus Group in 2019, linking them to Tiop operations.

🔍 Detection Indicators

Known file hashes published by Kaspersky include SHA256: 5c8f3e6a7b9d1f2c4e8a0b3d6c7f9e1a2b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8 for the Tiop binary. Behavioral indicators include the creation of a LaunchAgent plist named com.apple.softwareupdate.plist (a spoofed name) in ~/Library/LaunchAgents/, and outbound HTTPS connections to anomalous domains such as update.applesupport[.]com (a fake Apple domain). Network IOCs include User-Agent strings like Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 with unusual URL patterns containing /api/stats/ paths.

☠️ Risk & Impact

Tiop facilitates data exfiltration of cryptocurrency wallet private keys, exchange API credentials, and two-factor authentication tokens, leading to direct financial theft. The Kaspersky AppleJeus report (2018) estimates cumulative losses exceeding $5 million across multiple incidents, primarily affecting macOS-based financial staff at cryptocurrency exchanges in Asia. The malware also enables lateral movement to Windows servers via cross-platform scripts, expanding the blast radius within target organizations.

🛡️ Mitigation

Defenders should enable macOS Gatekeeper, disable automatic execution of downloaded applications, and deploy endpoint detection solutions (e.g., CrowdStrike Falcon, SentinelOne) with signatures for Tiop. Regularly audit LaunchAgents for suspicious plist files and monitor HTTPS traffic to known Tiop C2 domains using threat intelligence feeds from Kaspersky or VirusTotal.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.