New Mac Malware Hides in Memory and Masquerades as a Crypto App
A new form of malware is almost invisible to anti-virus software.

So-called "fileless" malware is infecting Mac OS machines by hiding in memory and never touching files or drives. The malware, masquerading as a piece of crypto trading software called UnionCryptoTrader.dmg, is suspected to be the work of the North Korean hacking group, Lazurus APT.
The malware infects Mac OS computers by injecting an executable file into the boot process, thereby hiding it from the user and rendering it difficult to remove. The executable then looks for various online payloads and runs them in memory, ensuring that anti-virus software could miss the malware after reboots and other OS events. Ultimately, there is very little for an anti-virus app to find as the payload changes over time and the malware has root privileges on infected machines.
The malware is based on AppleJeus by the Lazarus APT Group, a North Korean hacking outfit, and comes from a lineage of fileless Windows and Mac OS Trojans that masquerade as crypto trading apps.
The attackers created a legitimate-sounding crypto trading website called JMTTrading that offered a "smart cryptocurrency arbitrage trading platform." The website is currently live but doesn't seem to be delivering its malware payload anymore.

Another #Lazarus #macOS #trojan
— Dinesh_Devadoss (@dineshdina04) December 3, 2019
md5: 6588d262529dc372c400bef8478c2eec
hxxps://unioncrypto.vip/
Contains code: Loads Mach-O from memory and execute it / Writes to a file and execute it@patrickwardle @thomasareed pic.twitter.com/Mpru8FHELi
"It seems reasonable to assume that Lazarus Group is sticking with its successful attack vector (of targeting employees of crypto-currency exchanges with trojanized trading applications) …for now!" wrote Patrick Wardle on security site Objective-See.
According to security research service VirusTotal, only 19 of 72 Mac OS anti-virus apps can detect the malware.
The U.S. Treasury Department previously sanctioned North Korean hacking groups for attempting to steal cryptocurrencies via malware in an effort to pay for military equipment.
“Treasury is taking action against North Korean hacking groups that have been perpetrating cyber attacks to support illicit weapon and missile programs,” said Sigal Mandelker, Treasury Under Secretary for Terrorism and Financial Intelligence in September. “We will continue to enforce existing U.S. and UN sanctions against North Korea and work with the international community to improve cybersecurity of financial networks.”
As reporter Dan Goodin notes, the malware will bring up multiple password requests before it infects your computer, ensuring that only users most in need of fake crypto software will be infected which is obviously cold comfort for those who clicked through and installed the new Trojan.
Main Image Via Twitter
More For You
Protocol Research: GoPlus Security

What to know:
- As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
- GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
- Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.
More For You
NFT Project Pudgy Penguins Takes Over Las Vegas Sphere in Holiday Campaign

The NFT brand’s animated segments will air on the Sphere across Christmas week, signaling the crypto company's move into real-world consumer markets.
What to know:
- Pudgy Penguins will run an ad campaign at the Las Vegas Sphere during Christmas week, one of the few crypto brands to secure a spot at the high-profile venue.
- The NFT project, which launched on Ethereum in 2021, has expanded into physical toys and digital gaming as part of a broader consumer push.
- Pudgy Penguins briefly overtook Bored Apes in floor price earlier this year and recently launched its PENGU token on Solana, now trading on major exchanges.











