Also known as: APT28, Pawn Storm, Fancy Bear, Sednit, Bladabindi, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, MiniDionis, Hammertoss, Chinastrats, Patchwork
JuiceLedger is a threat actor known for infostealing through their JuiceStealer .NET assembly. They have evolved from spreading fraudulent applications to conducting supply chain attacks, targeting PyPI contributors with phishing campaigns and typosquatting. Their malicious packages contain a code snippet that downloads and executes JuiceStealer, which has evolved to support additional browsers and Discord. Victims of JuiceLedger attacks are advised to reset passwords and report any suspicious activity to security@pypi.org.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
JuiceLedger is a threat actor leveraging supply chain attacks and phishing campaigns to deploy JuiceStealer, a .NET-based info-stealer. Targets include PyPI contributors, with attacks evolving from fraudulent app distribution to malicious package injections. Victims are advised to reset passwords and report suspicious activity to PyPI's security team.
Goals & Targeting
JuiceLedger's strategic objectives revolve around compromising software supply chains to infiltrate organizations through trusted dependencies. By targeting PyPI contributors, they exploit the trust inherent in open-source ecosystems to distribute malware under legitimate software names. Their primary motivation appears to be credential theft, enabling access to sensitive systems and potentially broader network compromises. This actor typically targets developers, maintainers, and organizations reliant on Python packages, with a focus on sectors utilizing open-source software for infrastructure and application development.
Enhanced Description
JuiceLedger has transitioned from distributing fraudulent applications to sophisticated supply chain attacks, exploiting PyPI (Python Package Index) contributors through targeted phishing and typosquatting techniques. By injecting malicious code into legitimate software packages, the group triggers the download and execution of JuiceStealer, a malware assembly that has expanded in capability to support additional browsers and Discord. This evolution highlights their focus on compromising trusted software repositories to deploy payloads under the guise of legitimate updates. Victims, particularly developers and maintainers in the Python ecosystem, face risks of credential theft and lateral movement within compromised systems. The group's tactics emphasize deception and exploitation of package management vulnerabilities to maintain persistence and exfiltrate sensitive data.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
JuiceLedger's campaigns are characterized by persistent supply chain infiltration, with a focus on PyPI repository compromise through typosquatting and phishing. Their operations suggest a low operational tempo, targeting specific high-value individuals rather than widespread attacks. Notable past operations include the injection of malicious code into legitimate packages, leading to JuiceStealer deployment. The group's reliance on open-source ecosystems indicates a focus on sectors with heavy Python dependency, such as tech, finance, and academia.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in JuiceLedger's activities is moderate, based on observable malware deployments (JuiceStealer) and supply chain infiltration patterns. Gaps exist in understanding their sophistication level, primary motivation, and potential affiliations with other threat groups. Limited public reporting on their operational infrastructure or geopolitical ties reduces certainty in broader strategic objectives.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
40
Tools
0
Campaigns
39
IOCs
0
Observed Data
0
Tactics