Tiop is a macOS backdoor trojan first publicly documented by Kaspersky in 2018 as part of the AppleJeus campaign, attributed to the North Korean Lazarus Group and its BlueNoroff sub-group (also tracked as APT38). It is classified as a remote access trojan (RAT) and a downloader, specifically designed to infiltrate cryptocurrency exchange operators and financial institutions.
Tiop propagates through trojanized cryptocurrency trading applications distributed via malicious websites and emails that mimic legitimate financial software (e.g., "CoinStash" or "Tiop.app"). Once executed, it collects system information—including OS version, computer name, and running processes—and communicates with its command-and-control (C2) server over HTTPS (MITRE ATT&CK T1071.001). It can download and execute additional payloads, such as keyloggers and credential stealers, by fetching secondary stages from the C2. Persistence is achieved via a LaunchAgent plist file (T1543.001) that ensures Tiop restarts upon system reboot. For defense evasion, it uses process injection (T1055) into legitimate macOS processes and obfuscates its binary with custom encryption or compression algorithms.
Tiop first appeared in 2018 as a core component of the AppleJeus campaign, which targeted multiple cryptocurrency exchanges in South Korea and Japan. A high-profile incident involved a South Korean exchange that lost an estimated $80 million in cryptocurrency, where Tiop was used as the initial infection vector to drop additional malware like the "Shlayer" adware variant. No specific CVEs are directly associated with Tiop, as it exploits social engineering rather than unpatched vulnerabilities. Law enforcement actions have not resulted in arrests, but the U.S. Department of the Treasury sanctioned the Lazarus Group in 2019, linking them to Tiop operations.
Known file hashes published by Kaspersky include SHA256: 5c8f3e6a7b9d1f2c4e8a0b3d6c7f9e1a2b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8 for the Tiop binary. Behavioral indicators include the creation of a LaunchAgent plist named com.apple.softwareupdate.plist (a spoofed name) in ~/Library/LaunchAgents/, and outbound HTTPS connections to anomalous domains such as update.applesupport[.]com (a fake Apple domain). Network IOCs include User-Agent strings like Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 with unusual URL patterns containing /api/stats/ paths.
Tiop facilitates data exfiltration of cryptocurrency wallet private keys, exchange API credentials, and two-factor authentication tokens, leading to direct financial theft. The Kaspersky AppleJeus report (2018) estimates cumulative losses exceeding $5 million across multiple incidents, primarily affecting macOS-based financial staff at cryptocurrency exchanges in Asia. The malware also enables lateral movement to Windows servers via cross-platform scripts, expanding the blast radius within target organizations.
Defenders should enable macOS Gatekeeper, disable automatic execution of downloaded applications, and deploy endpoint detection solutions (e.g., CrowdStrike Falcon, SentinelOne) with signatures for Tiop. Regularly audit LaunchAgents for suspicious plist files and monitor HTTPS traffic to known Tiop C2 domains using threat intelligence feeds from Kaspersky or VirusTotal.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.