AppleSeed

S0622

Malware.View on attack.mitre.org

About this malware

AppleSeed is a backdoor that has been used by Kimsuky to target South Korean government, academic, and commercial targets since at least 2021.

Techniques used32

Procedure examples32

TechniqueProcedure example
T1005
Data from Local System

AppleSeed can collect data on a compromised host.

T1008
Fallback Channels

AppleSeed can use a second channel for C2 when the primary channel is in upload mode.

T1016
System Network Configuration Discovery

AppleSeed can identify the IP of a targeted system.

T1025
Data from Removable Media

AppleSeed can find and collect data from removable media devices.

T1027
Obfuscated Files or Information

AppleSeed has the ability to Base64 encode its payload and custom encrypt API calls.

T1027.002
Software Packing

AppleSeed has used UPX packers for its payload DLL.

T1030
Data Transfer Size Limits

AppleSeed has divided files if the size is 0x1000000 bytes or more.

T1036
Masquerading

AppleSeed can disguise JavaScript files as PDFs.

T1036.005
Match Legitimate Resource Name or Location

AppleSeed has the ability to rename its payload to ESTCommon.dll to masquerade as a DLL belonging to ESTsecurity.

T1041
Exfiltration Over C2 Channel

AppleSeed can exfiltrate files via the C2 channel.

T1056.001
Keylogging

AppleSeed can use GetKeyState and GetKeyboardState to capture keystrokes on the victim’s machine.

T1057
Process Discovery

AppleSeed can enumerate the current process on a compromised host.

T1059.001
PowerShell

AppleSeed has the ability to execute its payload via PowerShell.

T1059.007
JavaScript

AppleSeed has the ability to use JavaScript to execute PowerShell.

T1070.004
File Deletion

AppleSeed can delete files from a compromised host after they are exfiltrated.

View all 32 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Malwarebytes Kimsuky June 2021 Open source
    Jazi, H. (2021, June 1). Kimsuky APT continues to target South Korean government using AppleSeed backdoor. Retrieved June 10, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.