Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors JuiceLedger

Also known as: APT28, Pawn Storm, Fancy Bear, Sednit, Bladabindi, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, MiniDionis, Hammertoss, Chinastrats, Patchwork

Description

JuiceLedger is a threat actor known for infostealing through their JuiceStealer .NET assembly. They have evolved from spreading fraudulent applications to conducting supply chain attacks, targeting PyPI contributors with phishing campaigns and typosquatting. Their malicious packages contain a code snippet that downloads and executes JuiceStealer, which has evolved to support additional browsers and Discord. Victims of JuiceLedger attacks are advised to reset passwords and report any suspicious activity to security@pypi.org.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Energy
Telecommunications
Media
Aerospace
Education
Information technology
Maritime
Manufacturing
Think tank
Healthcare
Pharmaceutical
Chemical
Mining
Utilities
Gaming
Hospitality
Legal services
Nuclear
Entertainment

Targeted Countries / Regions

US
CN
GB
IN
JP
DE
KR
IR
RU
SA
CA
TW
IL
FR
UA
TR
AU
KZ
PK
VN
PL
AE
SG
NL
BR
ES
IQ
BY
IT
SY
MX
RO
EG
AZ

AI Analysis

· 1 week ago

Executive Summary

JuiceLedger is a threat actor leveraging supply chain attacks and phishing campaigns to deploy JuiceStealer, a .NET-based info-stealer. Targets include PyPI contributors, with attacks evolving from fraudulent app distribution to malicious package injections. Victims are advised to reset passwords and report suspicious activity to PyPI's security team.

Goals & Targeting

JuiceLedger's strategic objectives revolve around compromising software supply chains to infiltrate organizations through trusted dependencies. By targeting PyPI contributors, they exploit the trust inherent in open-source ecosystems to distribute malware under legitimate software names. Their primary motivation appears to be credential theft, enabling access to sensitive systems and potentially broader network compromises. This actor typically targets developers, maintainers, and organizations reliant on Python packages, with a focus on sectors utilizing open-source software for infrastructure and application development.

Enhanced Description

JuiceLedger has transitioned from distributing fraudulent applications to sophisticated supply chain attacks, exploiting PyPI (Python Package Index) contributors through targeted phishing and typosquatting techniques. By injecting malicious code into legitimate software packages, the group triggers the download and execution of JuiceStealer, a malware assembly that has expanded in capability to support additional browsers and Discord. This evolution highlights their focus on compromising trusted software repositories to deploy payloads under the guise of legitimate updates. Victims, particularly developers and maintainers in the Python ecosystem, face risks of credential theft and lateral movement within compromised systems. The group's tactics emphasize deception and exploitation of package management vulnerabilities to maintain persistence and exfiltrate sensitive data.

Key Capabilities

  • Supply chain attack execution via malicious package injections
  • Phishing campaigns tailored to PyPI contributors
  • Typosquatting to deceive package downloaders
  • Malware deployment using JuiceStealer (supporting multi-browser and Discord exploitation)
  • Code injection techniques within legitimate software repositories

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Credential Access
Exfiltration

ATT&CK Techniques

T1192.002
T1105
T1056.001
T1036.001
T1040.001

Software / Tooling

JuiceStealer
Custom phishing infrastructure
Typosquatting scripts

Campaigns & Victims

JuiceLedger's campaigns are characterized by persistent supply chain infiltration, with a focus on PyPI repository compromise through typosquatting and phishing. Their operations suggest a low operational tempo, targeting specific high-value individuals rather than widespread attacks. Notable past operations include the injection of malicious code into legitimate packages, leading to JuiceStealer deployment. The group's reliance on open-source ecosystems indicates a focus on sectors with heavy Python dependency, such as tech, finance, and academia.

IOC Patterns

  • Spear-phishing emails with malicious attachment URLs
  • Typosquatting package names on PyPI
  • Suspicious .NET assemblies embedded in package repositories
  • C2 traffic via DNS tunneling or HTTP-based exfiltration

Recommended Actions

  • Monitor PyPI for typosquatting packages and report suspicious submissions
  • Implement strict code-signing and verification protocols for package dependencies
  • Deploy email filtering to detect phishing attempts targeting developers
  • Conduct network traffic analysis for anomalous DNS or HTTP activity
  • Reset credentials and enable MFA for PyPI accounts following suspected compromises

Suggested Tags

APT
supply-chain
info-stealing
PyPI
phishing

Confidence Assessment

Confidence in JuiceLedger's activities is moderate, based on observable malware deployments (JuiceStealer) and supply chain infiltration patterns. Gaps exist in understanding their sophistication level, primary motivation, and potential affiliations with other threat groups. Limited public reporting on their operational infrastructure or geopolitical ties reduces certainty in broader strategic objectives.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 16 SHA-1 Hash 3 Email Address 1

References

  1. www.sonatype.com — Cited by web research for: Bladabindi
  2. misp-galaxy.org — Cited by web research for: cpyy
  3. www.sentinelone.com — Cited by web research for: Void
  4. arstechnica.com — Cited by web research for: Dark
  5. www.sentinelone.com — Cited by web research for: Backdoors

Intel Summary

0

Techniques

40

Tools

0

Campaigns

39

IOCs

0

Observed Data

0

Tactics

Tags

Supply Chain Attack
Phishing
APT
supply-chain
info-stealing
PyPI
phishing

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.