AppleJeus

S0584

Malware.View on attack.mitre.org

About this malware

AppleJeus is a family of downloaders initially discovered in 2018 embedded within trojanized cryptocurrency applications. AppleJeus has been used by Lazarus Group, targeting companies in the energy, finance, government, industry, technology, and telecommunications sectors, and several countries including the United States, United Kingdom, South Korea, Australia, Brazil, New Zealand, and Russia. AppleJeus has been used to distribute the FALLCHILL RAT.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1027
Obfuscated Files or Information

AppleJeus has XOR-encrypted collected system information prior to sending to a C2. AppleJeus has also used the open source ADVObfuscation library for its components.

T1041
Exfiltration Over C2 Channel

AppleJeus has exfiltrated collected host information to a C2 server.

T1053.005
Scheduled Task

AppleJeus has created a scheduled SYSTEM task that runs when a user logs in.

T1059.004
Unix Shell

AppleJeus has used shell scripts to execute commands after installation and set persistence mechanisms.

T1070.004
File Deletion

AppleJeus has deleted the MSI file after installation.

T1071.001
Web Protocols

AppleJeus has sent data to its C2 server via POST requests.

T1082
System Information Discovery

AppleJeus has collected the victim host information after infection.

T1140
Deobfuscate/Decode Files or Information

AppleJeus has decoded files received from a C2.

T1204.001
Malicious Link

AppleJeus's spearphishing links required user interaction to navigate to the malicious website.

T1204.002
Malicious File

AppleJeus has required user execution of a malicious MSI installer.

T1218.007
Msiexec

AppleJeus has been installed via MSI installer.

T1497.003
Time Based Checks

AppleJeus has waited a specified time before downloading a second stage payload.

T1543.003
Windows Service

AppleJeus can install itself as a service.

T1543.004
Launch Daemon

AppleJeus has placed a plist file within the LaunchDaemons folder and launched it manually.

T1546.016
Installer Packages

During AppleJeus's installation process, it uses `postinstall` scripts to extract a hidden plist from the application's `/Resources` folder and execute the `plist` file as a Launch Daemon with elevated permissions.

View all 20 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. CISA AppleJeus Feb 2021 Open source
    Cybersecurity and Infrastructure Security Agency. (2021, February 21). AppleJeus: Analysis of North Korea’s Cryptocurrency Malware. Retrieved March 1, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.