{"id":97604,"date":"2023-04-02T10:19:49","date_gmt":"2023-04-02T17:19:49","guid":{"rendered":"https:\/\/www.intego.com\/mac-security-blog\/?p=97604"},"modified":"2023-04-07T11:53:45","modified_gmt":"2023-04-07T18:53:45","slug":"smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/","title":{"rendered":"SmoothOperator: 3CX VoIP app spreads Mac malware by Lazarus Group APT"},"content":{"rendered":"<p><img loading=\"lazy\" class=\"aligncenter size-full wp-image-97622\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/04\/malware-emerging-from-telephone-600x350-1.jpg\" alt=\"\" width=\"600\" height=\"350\" \/><\/p>\n<p>SmoothOperator is one of three new Mac-infecting malware families that came to light in March (the others being <a href=\"https:\/\/www.intego.com\/mac-security-blog\/fakegpt-trojanized-chatgpt-chrome-extension-hijacks-facebook-accounts\/\">FakeGPT<\/a> and <a href=\"https:\/\/www.intego.com\/mac-security-blog\/macstealer-mac-trojan-malware-steals-passwords-wallets-and-files\/\">MacStealer<\/a>).<\/p>\n<p>Let&#8217;s take a look at what SmoothOperator does, who&#8217;s behind the campaign, and how you can avoid or clean up an infection.<\/p>\n<h3>What should I know about SmoothOperator?<\/h3>\n<p>SmoothOperator is a malware campaign built upon what&#8217;s known as a software supply chain attack. In other words, the normal distribution method for some legitimate software was compromised and infected with malware.<\/p>\n<p>We&#8217;ve seen supply chain attacks on Mac software before; for example, the BitTorrent client app Transmission was compromised twice in 2016, once to distribute <a href=\"https:\/\/www.intego.com\/mac-security-blog\/mac-users-hit-by-rare-ransomware-attack-spread-via-transmission-bittorrent-app\/\">KeRanger ransomware<\/a> and later to steal macOS Keychain contents via <a href=\"https:\/\/www.intego.com\/mac-security-blog\/malware-spreads-through-modified-transmission-application-again\/\">Keydnap malware<\/a>.<\/p>\n<p>But in this case, SmoothOperator was the work of a sophisticated, nation-state level attacker, also known as an advanced persistent threat (APT). The particular APT group in this case is believed to be <a href=\"https:\/\/www.intego.com\/mac-security-blog\/topic\/lazarus-group\/\">Lazarus Group<\/a>, best known among Mac users for its <a href=\"https:\/\/www.intego.com\/mac-security-blog\/operation-applejeus-and-osxlazarus-rise-of-a-mac-apt\/\">Operation AppleJeus<\/a> campaign.<\/p>\n<p>Apparently, as part of the SmoothOperator campaign, the Lazarus Group compromised the servers of voice over IP (VoIP) software maker 3CX, and maliciously modified both its Windows and macOS desktop client apps.<\/p>\n<p>Users of the software began to get warnings from their antivirus software<span style=\"font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Oxygen-Sans, Ubuntu, Cantarell, 'Helvetica Neue', sans-serif;\">\u00a0<\/span><span style=\"font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Oxygen-Sans, Ubuntu, Cantarell, 'Helvetica Neue', sans-serif;\">on March 22<\/span><span style=\"font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Oxygen-Sans, Ubuntu, Cantarell, 'Helvetica Neue', sans-serif;\"> that something seemed amiss, but 3CX&#8217;s tech support representative dismissed it as a false positive and <a href=\"https:\/\/arstechnica.com\/information-technology\/2023\/03\/3cx-knew-its-app-was-flagged-as-malicious-but-took-no-action-for-7-days\/\" target=\"_blank\" rel=\"noopener\">blamed the antivirus vendor<\/a>. Unfortunately, it turned out that the company&#8217;s software was, in fact, infected after all.<\/span><\/p>\n<h3>How can one remove or prevent SmoothOperator and other Mac malware?<\/h3>\n<p><img loading=\"lazy\" class=\"alignright size-medium wp-image-54214\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/06\/X9-Mac-Antivirus-Launch-300x150.png\" alt=\"Intego X9 software boxes\" width=\"200\" height=\"100\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/06\/X9-Mac-Antivirus-Launch-300x150.png 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/06\/X9-Mac-Antivirus-Launch-150x75.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/06\/X9-Mac-Antivirus-Launch.png 600w\" sizes=\"(max-width: 200px) 100vw, 200px\" \/><\/p>\n<p>Intego VirusBarrier X9, included with <strong><a href=\"https:\/\/www.intego.com\/mac-protection-bundle\">Intego&#8217;s Mac Premium Bundle X9<\/a><\/strong>, can protect against, detect, and eliminate this Mac malware.<\/p>\n<p>If you believe your Mac may be infected, or to prevent future infections, it&#8217;s best to use antivirus software from a trusted Mac developer. VirusBarrier is award-winning antivirus software, designed by Mac security experts, that includes <a href=\"https:\/\/www.intego.com\/mac-security-blog\/why-your-antivirus-needs-real-time-scanning\/\">real-time protection<\/a>. It runs natively on a wide range of Mac hardware and operating systems, including the latest Apple silicon Macs running macOS Ventura.<\/p>\n<p>If you use a Windows PC, <a href=\"https:\/\/www.intego.com\/intego-antivirus\"><strong>Intego Antivirus for Windows<\/strong><\/a> can keep your computer protected from PC malware.<\/p>\n<p><span style=\"font-size: small;\">Note: Intego customers running VirusBarrier X8, X7, or X6 on older versions of Mac OS X are also protected from this threat. It is best to upgrade to the latest versions of VirusBarrier and macOS, if possible, to ensure your Mac gets all the latest security updates from Apple.<\/span><a name=\"learnmore\"><\/a><\/p>\n<h3>How can I learn more?<\/h3>\n<p>For additional technical information about the SmoothOperator malware, you can refer to the original write-up by <a href=\"https:\/\/www.crowdstrike.com\/blog\/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers\/\" target=\"_blank\" rel=\"noopener nofollow\">CrowdStrike<\/a> and the <a href=\"https:\/\/objective-see.org\/blog\/blog_0x73.html\" target=\"_blank\" rel=\"noopener nofollow\">first<\/a>\u00a0and <a href=\"https:\/\/objective-see.org\/blog\/blog_0x74.html\" target=\"_blank\" rel=\"noopener nofollow\">second<\/a> write-ups of the Mac version by Patrick Wardle.<\/p>\n<p>We briefly discussed Honkbox on <a href=\"https:\/\/podcast.intego.com\/286\">episode 286<\/a>\u00a0of the Intego Mac Podcast:<\/p>\n<p><iframe loading=\"lazy\" src=\"https:\/\/player.fireside.fm\/v2\/GegHgcrH+8fL7AAhz?theme=dark\" width=\"740\" height=\"200\" frameborder=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<p>Each week on the <a href=\"https:\/\/podcast.intego.com\/\" target=\"_blank\" rel=\"noopener\"><strong>Intego Mac Podcast<\/strong><\/a>, Intego&#8217;s Mac security experts discuss the latest Apple news, including security and privacy stories, and offer practical advice on getting the most out of your Apple devices. Be sure to <a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" rel=\"noopener\"><strong>follow the podcast<\/strong><\/a> to make sure you don\u2019t miss any episodes.<\/p>\n<p>You can also subscribe to our <a href=\"https:\/\/www.intego.com\/mac-security-blog\/mac-security-newsletter\/\"><strong>e-mail newsletter<\/strong><\/a> and keep an eye here on <a href=\"https:\/\/www.intego.com\/mac-security-blog\"><strong>The Mac Security Blog<\/strong><\/a> for the latest Apple security and privacy news. And don&#8217;t forget to follow Intego on your favorite social media channels: <a href=\"https:\/\/twitter.com\/IntegoSecurity\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on Twitter\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/10\/Twitter-logo-icon-64.png\" alt=\"Follow Intego on Twitter\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.facebook.com\/Intego\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on Facebook\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/10\/Facebook-logo-icon-64.png\" alt=\"Follow Intego on Facebook\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.youtube.com\/user\/IntegoVideo?sub_confirmation=1\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(0, 0, 0, 0.2); border-radius: 8px;\" title=\"Follow Intego on YouTube\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/10\/YouTube-logo-icon-64.png\" alt=\"Follow Intego on YouTube\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.pinterest.com\/intego\/\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(0, 0, 0, 0.2); border-radius: 8px;\" title=\"Follow Intego on Pinterest\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/10\/Pinterest-logo-icon-64.png\" alt=\"Follow Intego on Pinterest\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/intego\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on LinkedIn\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/10\/LinkedIn-logo-icon-64.png\" alt=\"Follow Intego on LinkedIn\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.instagram.com\/intego_security\/\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on Instagram\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/10\/Instagram-logo-icon-64.png\" alt=\"Follow Intego on Instagram\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow the Intego Mac Podcast on Apple Podcasts\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile.png\" alt=\"Follow the Intego Mac Podcast on Apple Podcasts\" width=\"16\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SmoothOperator is one of three new Mac-infecting malware families that came to light in March (the others being FakeGPT and MacStealer). Let&#8217;s take a look at what SmoothOperator does, who&#8217;s behind the campaign, and how you can avoid or clean up an infection. What should I know about SmoothOperator? SmoothOperator is a malware campaign built [&hellip;]<\/p>\n","protected":false},"author":14,"featured_media":97621,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"SmoothOperator: 3CX VoIP app spreads Mac malware by Lazarus Group APT","jetpack_is_tweetstorm":false},"categories":[190],"tags":[4291,4288,86],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"SmoothOperator is one of three new Mac-infecting malware families that came to light in March (the others being FakeGPT and MacStealer). Let&#039;s take a look\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SmoothOperator: 3CX VoIP app spreads Mac malware by Lazarus Group APT - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"SmoothOperator is one of three new Mac-infecting malware families that came to light in March (the others being FakeGPT and MacStealer). Let&#039;s take a look\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/JoshLong\" \/>\n<meta property=\"article:published_time\" content=\"2023-04-02T17:19:49+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-04-07T18:53:45+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/04\/malware-emerging-from-telephone-400x260-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"260\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@theJoshMeister\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Joshua Long\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/04\/malware-emerging-from-telephone-400x260-1.jpg\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/04\/malware-emerging-from-telephone-400x260-1.jpg\",\"width\":400,\"height\":260,\"caption\":\"SmoothOperator 3CX VoIP supply chain attack Lazarus Group APT malware emerging from a telephone\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/\",\"name\":\"SmoothOperator: 3CX VoIP app spreads Mac malware by Lazarus Group APT - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/#primaryimage\"},\"datePublished\":\"2023-04-02T17:19:49+00:00\",\"dateModified\":\"2023-04-07T18:53:45+00:00\",\"description\":\"SmoothOperator is one of three new Mac-infecting malware families that came to light in March (the others being FakeGPT and MacStealer). Let's take a look\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SmoothOperator: 3CX VoIP app spreads Mac malware by Lazarus Group APT\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1\"},\"headline\":\"SmoothOperator: 3CX VoIP app spreads Mac malware by Lazarus Group APT\",\"datePublished\":\"2023-04-02T17:19:49+00:00\",\"dateModified\":\"2023-04-07T18:53:45+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/#webpage\"},\"wordCount\":542,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/04\/malware-emerging-from-telephone-400x260-1.jpg\",\"keywords\":[\"Advanced Persistent Threats (APT)\",\"Lazarus Group\",\"Malware\"],\"articleSection\":[\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1\",\"name\":\"Joshua Long\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g\",\"caption\":\"Joshua Long\"},\"description\":\"Joshua Long (@theJoshMeister), formerly Intego\\u2019s Chief Security Analyst, is a renowned security researcher and writer, and an award-winning public speaker. Josh has a master\\u2019s degree in IT concentrating in Internet Security and has taken doctorate-level coursework in Information Security. Apple has publicly acknowledged Josh for discovering an Apple\\u00a0ID authentication vulnerability. Josh has conducted cybersecurity research for well over 25 years, which is often featured by major news outlets worldwide. Keep up with Josh via X\/Twitter, LinkedIn, Facebook, Instagram, YouTube, Patreon, Mastodon, the JoshMeister on Security, and more. \\u2014\",\"sameAs\":[\"https:\/\/security.thejoshmeister.com\",\"https:\/\/www.facebook.com\/JoshLong\",\"https:\/\/www.instagram.com\/thejoshmeister\/\",\"https:\/\/www.linkedin.com\/in\/thejoshmeister\",\"https:\/\/www.pinterest.com\/thejoshmeister\/\",\"https:\/\/twitter.com\/theJoshMeister\",\"https:\/\/www.youtube.com\/@theJoshMeister\"],\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"SmoothOperator is one of three new Mac-infecting malware families that came to light in March (the others being FakeGPT and MacStealer). Let's take a look","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/","og_locale":"en_US","og_type":"article","og_title":"SmoothOperator: 3CX VoIP app spreads Mac malware by Lazarus Group APT - The Mac Security Blog","og_description":"SmoothOperator is one of three new Mac-infecting malware families that came to light in March (the others being FakeGPT and MacStealer). Let's take a look","og_url":"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/","og_site_name":"The Mac Security Blog","article_author":"https:\/\/www.facebook.com\/JoshLong","article_published_time":"2023-04-02T17:19:49+00:00","article_modified_time":"2023-04-07T18:53:45+00:00","og_image":[{"width":400,"height":260,"url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/04\/malware-emerging-from-telephone-400x260-1.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_creator":"@theJoshMeister","twitter_misc":{"Written by":"Joshua Long","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/04\/malware-emerging-from-telephone-400x260-1.jpg","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/04\/malware-emerging-from-telephone-400x260-1.jpg","width":400,"height":260,"caption":"SmoothOperator 3CX VoIP supply chain attack Lazarus Group APT malware emerging from a telephone"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/","name":"SmoothOperator: 3CX VoIP app spreads Mac malware by Lazarus Group APT - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/#primaryimage"},"datePublished":"2023-04-02T17:19:49+00:00","dateModified":"2023-04-07T18:53:45+00:00","description":"SmoothOperator is one of three new Mac-infecting malware families that came to light in March (the others being FakeGPT and MacStealer). Let's take a look","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"SmoothOperator: 3CX VoIP app spreads Mac malware by Lazarus Group APT"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1"},"headline":"SmoothOperator: 3CX VoIP app spreads Mac malware by Lazarus Group APT","datePublished":"2023-04-02T17:19:49+00:00","dateModified":"2023-04-07T18:53:45+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/#webpage"},"wordCount":542,"commentCount":0,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/04\/malware-emerging-from-telephone-400x260-1.jpg","keywords":["Advanced Persistent Threats (APT)","Lazarus Group","Malware"],"articleSection":["Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intego.com\/mac-security-blog\/smoothoperator-3cx-voip-app-spreads-mac-malware-by-lazarus-group-apt\/#respond"]}]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1","name":"Joshua Long","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g","caption":"Joshua Long"},"description":"Joshua Long (@theJoshMeister), formerly Intego\u2019s Chief Security Analyst, is a renowned security researcher and writer, and an award-winning public speaker. Josh has a master\u2019s degree in IT concentrating in Internet Security and has taken doctorate-level coursework in Information Security. Apple has publicly acknowledged Josh for discovering an Apple\u00a0ID authentication vulnerability. Josh has conducted cybersecurity research for well over 25 years, which is often featured by major news outlets worldwide. Keep up with Josh via X\/Twitter, LinkedIn, Facebook, Instagram, YouTube, Patreon, Mastodon, the JoshMeister on Security, and more. \u2014","sameAs":["https:\/\/security.thejoshmeister.com","https:\/\/www.facebook.com\/JoshLong","https:\/\/www.instagram.com\/thejoshmeister\/","https:\/\/www.linkedin.com\/in\/thejoshmeister","https:\/\/www.pinterest.com\/thejoshmeister\/","https:\/\/twitter.com\/theJoshMeister","https:\/\/www.youtube.com\/@theJoshMeister"],"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/"}]}},"jetpack_featured_media_url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/04\/malware-emerging-from-telephone-400x260-1.jpg","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-pog","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/97604"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=97604"}],"version-history":[{"count":5,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/97604\/revisions"}],"predecessor-version":[{"id":97674,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/97604\/revisions\/97674"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/97621"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=97604"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=97604"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=97604"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}