Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors AppleJeus

Also known as: Gleaming Pisces, Citrine Sleet, UNC1720, UNC4736, tracked as, APT38

Description

AppleJeus is a versatile downloader family first identified in 2018 that infects macOS, Linux and Windows hosts through trojanized cryptocurrency trading platforms such as BloxHolder or counterfeit front‑ends. Compromise is achieved primarily via spear‑phishing links or compromised websites hosting the disguised installer. Once executed, AppleJeus establishes a lightweight backdoor that enumerates system information, obfuscates its payloads, and exfiltrates crypto wallets or mined coins to remote command‑and‑control nodes. Beyond initial infection, AppleJeus demonstrates sophisticated persistence mechanisms: creating launch daemons on macOS, scheduled tasks on Windows, DLL side‑loading chains, and memory‑resident RATs such as RemotePE. The actor also expands footprint through supply‑chain attacks—poisoning third‑party Python packages (e.g., VMConnect) or 3CX installers—to deliver multi‑platform backdoors. The group blends financial theft with credential harvesting and potential sabotage capabilities. While most documented operations focus on cryptocurrency theft, AppleJeus has recently leveraged the Chromium zero‑day CVE‑2024‑7971 to pivot into industrial targets, illustrating a dual espionage‑and‑robbery mandate. The attacker’s modus operandi reflects Lazarus Group’s broader infrastructure of resource sharing under the Reconnaissance General Bureau umbrella. AppleJeus continues to evolve its techniques: it uses reflective code loading, cookie‑based C2 channels in HTTPS requests, and timed stealth features that delay execution for several weeks. This breadth of capability positions AppleJeus as a potent threat to both the crypto industry and high‑value financial or industrial victim sectors.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Government
Media
Transportation
Entertainment
Aerospace
Telecommunications
Energy
Healthcare
Maritime
Gaming
Critical infrastructure
Chemical

Targeted Countries / Regions

KP
KR
US
JP
IN
SG
GB
IL
NL

AI Analysis

Grounded in web research
· 1 day ago

Executive Summary

AppleJeus is a North Korean state-sponsored downloader linked to the Lazarus Group. It masquerades as counterfeit cryptocurrency trading applications, delivers persistent backdoors via macOS launch daemons and Windows scheduled tasks, then steals wallets or mined coins while maintaining covert remote command-and-control channels. Recent campaigns have also exposed supply‑chain poisoning of Python packages and a Chromium zero‑day exploit, highlighting a dual robbery‑espionage approach.

Goals & Targeting

AppleJeus is driven primarily by state-funded financial gain; its operations are tailored to monetize cryptocurrency assets and illicitly launder revenue for the DPRK. The actor focuses on sectors that generate substantial digital asset holdings—crypto exchanges, mining farms, high‑net‑worth traders—and expands into broader finance, transportation, maritime, and critical infrastructure domains when additional credential or sabotage payloads can be leveraged for espionage or economic disruption. Typical victims include organizations with open web interfaces, employees who fall for phishing lures, and developers of third‑party software libraries prone to supply‑chain compromise.

Enhanced Description

Key Capabilities

  • Multi‑platform downloader (macOS/Linux/Windows)
  • Spear‑phishing links via malicious URLs
  • Trojanized cryptocurrency trading apps as delivery vector
  • Launch daemon persistence on macOS
  • Scheduled task persistence on Windows
  • DLL side‑loading chains
  • Memory‑resident RATs such as RemotePE and POOLRAT
  • Supply chain poisoning of Python packages (VMConnect) and 3CX installers
  • Exfiltration over HTTPS with cookie‑based C2 channels
  • Use of Chromium CVE‑2024‑7971 for exploitation and pivot
  • Stealth mechanisms including deferred execution
  • Credential harvesting via IconicStealer

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Collection
Exfiltration
Command and Control

ATT&CK Techniques

T1204.002
T1566.002
T1543
T1055
T1573
T1071
T1082
T1102
T1546
T1195
T1620
T1218
T1559
T1574
T1518

Software / Tooling

AppleJeus
REMOTEPE
POOLRAT
IconicStealer
3CX Supply Chain Backdoor
Citrine Sleet malware suite
Gleaming Pisces tools

Campaigns & Victims

AppleJeus operates in a recurring, high‑tempo campaign sequence where the threat actor first distributes counterfeit crypto trading apps to create initial footholds. After compromising an environment, it deploys additional backdoors and executes supply‑chain poisoning of third‑party libraries or commercial installers (e.g., 3CX). Victim profiles skew toward financial services and cryptocurrency exchanges, but the group also infiltrates defense contractors and other high‑value sectors when opportunities arise. Key patterns include: - Launching via spear‑phishing links or compromised sites hosting disguised installers. - Persistence through launch daemons (macOS) or scheduled tasks (Windows). - Supply chain attacks targeting Python packages or commercial VoIP software. - Use of zero‑day browser exploits (CVE‑2022‑0609, CVE‑2024‑7971) and drive‑by compromise websites to gain client execution. Notable past operations include the 2018 Operation AppleJeus targeting a cryptocurrency exchange, the 2020 “AppleJeus sequel” with enhanced distribution tactics, February 2022’s lolZarus campaign using employment phishing lures against defense targets, and September 2024 Gleaming Pisces’ poisoned Python package delivery of PondRAT and POOLRAT backdoors.

IOC Patterns

  • Spear‑phishing links to counterfeit crypto trading app installers
  • Trojanized installer with embedded downloader for macOS/Linux/Windows
  • Supply‑chain poisoning of third‑party Python packages (e.g., VMConnect) or 3CX installers
  • Use of launch daemons on macOS and scheduled tasks on Windows as persistence mechanism
  • Memory‑resident RATs like RemotePE and POOLRAT
  • Cookie‑based HTTPS C2 channel with hardcoded variables in requests
  • Deferred execution via random timestamps for stealth

Recommended Actions

  • Block known malicious domains and IP ranges associated with AppleJeus (e.g., rebelthumb.net, falconfeeds.io, temp.hermit).
  • Implement strict least‑privilege policies and disable user execution of unsigned or downloaded binaries on macOS/Linux/Windows.
  • Deploy endpoint detection & response solutions that detect downloader patterns, launch daemon installation, and memory‑resident RAT signatures.
  • Patch critical browser and operating system CVEs (especially Chrome CVE‑2024‑7971) promptly and monitor for exploitation activity.
  • Segment networks to isolate cryptocurrency wallets and prevent lateral movement from compromised host.
  • Enforce multi‑factor authentication on all remote or privileged access accounts.
  • Educate employees on phishing, especially spear‑phishing links labeled as legitimate trading platforms.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. Mandiant 3cx UNC4736 2023 — Jeff Johnson, Fred Plan, Adrian Sanchez, Renato Fontana, Jake Nicastro, Dimiter Andonov, Marius Fodoreanu, Daniel Scott. (2023, April 20). 3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspected North Korean Actor Responsible. Retrieved August 25, 2025.
  2. dtex DPRK 2025 structure ITworkers — Michael “Barni” Barnhart, DTEX, and Anonymous SMEs. (2025, May 14). Exposing DPRK's Cyber Syndicate and Hidden IT Workforce. Retrieved September 3, 2025.
  3. Mandiant DPRK Groups 2023 — Michael Barnhart, Austin Larsen, Jeff Johnson, Taylor Long, Michelle Cantos, Adrian Hernandez. (2023, October 10). Assessed Cyber Structure and Alignments of North Korea in 2023. Retrieved August 25, 2025.
  4. Unit42 DPRK Threat Groups 2024 — Unit 42. (2024, September 9). Threat Assessment: North Korean Threat Groups. Retrieved August 25, 2025.
  5. JPCert Blog Laz Subgroups 2025 — 佐々木勇人 Hayato Sasaki. (2025, March 25). Tempted to Classifying APT Actors: Practical Challenges of Attribution in the Case of Lazarus’s Subgroup. Retrieved August 25, 2025.
  6. www.malwarebytes.com — Cited by web research for: APT38
  7. attack.mitre.org — Cited by web research for: T1071
  8. apt.etda.or.th — Cited by web research for: VEILEDSIGNAL

Intel Summary

27

Techniques

58

Tools

0

Campaigns

28

IOCs

0

Observed Data

9

Tactics

Tags

North Korea
State-Sponsored APT
Financial Theft
Cryptocurrency Threat
Lazarus Group

Details

MITRE ID
G1049
Type
Unknown
Primary Motivation
Financial gain
Country of Origin
K
Confidence
90%
Added
Jul 22, 2026
STIX ID
intrusion-set--14225573-63b5-4e50-ba9a-5fdcaf6a7b4c
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.