Also known as: Gleaming Pisces, Citrine Sleet, UNC1720, UNC4736, tracked as, APT38
AppleJeus is a versatile downloader family first identified in 2018 that infects macOS, Linux and Windows hosts through trojanized cryptocurrency trading platforms such as BloxHolder or counterfeit front‑ends. Compromise is achieved primarily via spear‑phishing links or compromised websites hosting the disguised installer. Once executed, AppleJeus establishes a lightweight backdoor that enumerates system information, obfuscates its payloads, and exfiltrates crypto wallets or mined coins to remote command‑and‑control nodes. Beyond initial infection, AppleJeus demonstrates sophisticated persistence mechanisms: creating launch daemons on macOS, scheduled tasks on Windows, DLL side‑loading chains, and memory‑resident RATs such as RemotePE. The actor also expands footprint through supply‑chain attacks—poisoning third‑party Python packages (e.g., VMConnect) or 3CX installers—to deliver multi‑platform backdoors. The group blends financial theft with credential harvesting and potential sabotage capabilities. While most documented operations focus on cryptocurrency theft, AppleJeus has recently leveraged the Chromium zero‑day CVE‑2024‑7971 to pivot into industrial targets, illustrating a dual espionage‑and‑robbery mandate. The attacker’s modus operandi reflects Lazarus Group’s broader infrastructure of resource sharing under the Reconnaissance General Bureau umbrella. AppleJeus continues to evolve its techniques: it uses reflective code loading, cookie‑based C2 channels in HTTPS requests, and timed stealth features that delay execution for several weeks. This breadth of capability positions AppleJeus as a potent threat to both the crypto industry and high‑value financial or industrial victim sectors.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
AppleJeus is a North Korean state-sponsored downloader linked to the Lazarus Group. It masquerades as counterfeit cryptocurrency trading applications, delivers persistent backdoors via macOS launch daemons and Windows scheduled tasks, then steals wallets or mined coins while maintaining covert remote command-and-control channels. Recent campaigns have also exposed supply‑chain poisoning of Python packages and a Chromium zero‑day exploit, highlighting a dual robbery‑espionage approach.
Goals & Targeting
AppleJeus is driven primarily by state-funded financial gain; its operations are tailored to monetize cryptocurrency assets and illicitly launder revenue for the DPRK. The actor focuses on sectors that generate substantial digital asset holdings—crypto exchanges, mining farms, high‑net‑worth traders—and expands into broader finance, transportation, maritime, and critical infrastructure domains when additional credential or sabotage payloads can be leveraged for espionage or economic disruption. Typical victims include organizations with open web interfaces, employees who fall for phishing lures, and developers of third‑party software libraries prone to supply‑chain compromise.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
AppleJeus operates in a recurring, high‑tempo campaign sequence where the threat actor first distributes counterfeit crypto trading apps to create initial footholds. After compromising an environment, it deploys additional backdoors and executes supply‑chain poisoning of third‑party libraries or commercial installers (e.g., 3CX). Victim profiles skew toward financial services and cryptocurrency exchanges, but the group also infiltrates defense contractors and other high‑value sectors when opportunities arise. Key patterns include: - Launching via spear‑phishing links or compromised sites hosting disguised installers. - Persistence through launch daemons (macOS) or scheduled tasks (Windows). - Supply chain attacks targeting Python packages or commercial VoIP software. - Use of zero‑day browser exploits (CVE‑2022‑0609, CVE‑2024‑7971) and drive‑by compromise websites to gain client execution. Notable past operations include the 2018 Operation AppleJeus targeting a cryptocurrency exchange, the 2020 “AppleJeus sequel” with enhanced distribution tactics, February 2022’s lolZarus campaign using employment phishing lures against defense targets, and September 2024 Gleaming Pisces’ poisoned Python package delivery of PondRAT and POOLRAT backdoors.
IOC Patterns
Recommended Actions
No campaigns linked yet.
No observed data linked yet.
27
Techniques
58
Tools
0
Campaigns
28
IOCs
0
Observed Data
9
Tactics