Malware.View on attack.mitre.org
AppleJeus is a family of downloaders initially discovered in 2018 embedded within trojanized cryptocurrency applications. AppleJeus has been used by Lazarus Group, targeting companies in the energy, finance, government, industry, technology, and telecommunications sectors, and several countries including the United States, United Kingdom, South Korea, Australia, Brazil, New Zealand, and Russia. AppleJeus has been used to distribute the FALLCHILL RAT.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
AppleJeus has XOR-encrypted collected system information prior to sending to a C2. AppleJeus has also used the open source ADVObfuscation library for its components. |
| T1041 Exfiltration Over C2 Channel |
AppleJeus has exfiltrated collected host information to a C2 server. |
| T1053.005 Scheduled Task |
AppleJeus has created a scheduled SYSTEM task that runs when a user logs in. |
| T1059.004 Unix Shell |
AppleJeus has used shell scripts to execute commands after installation and set persistence mechanisms. |
| T1070.004 File Deletion |
AppleJeus has deleted the MSI file after installation. |
| T1071.001 Web Protocols |
AppleJeus has sent data to its C2 server via |
| T1082 System Information Discovery |
AppleJeus has collected the victim host information after infection. |
| T1140 Deobfuscate/Decode Files or Information |
AppleJeus has decoded files received from a C2. |
| T1204.001 Malicious Link |
AppleJeus's spearphishing links required user interaction to navigate to the malicious website. |
| T1204.002 Malicious File |
AppleJeus has required user execution of a malicious MSI installer. |
| T1218.007 Msiexec |
AppleJeus has been installed via MSI installer. |
| T1497.003 Time Based Checks |
AppleJeus has waited a specified time before downloading a second stage payload. |
| T1543.003 Windows Service |
AppleJeus can install itself as a service. |
| T1543.004 Launch Daemon |
AppleJeus has placed a plist file within the |
| T1546.016 Installer Packages |
During AppleJeus's installation process, it uses `postinstall` scripts to extract a hidden plist from the application's `/Resources` folder and execute the `plist` file as a Launch Daemon with elevated permissions. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.