AppleJeus is a North Korea-linked threat actor and activity cluster associated with financially motivated intrusions, especially cryptocurrency theft, software supply-chain compromise, and social-engineering operations targeting the cryptocurrency and decentralized finance ecosystem. The cluster is widely tracked under multiple names including Citrine Sleet, UNC4736, Gleaming Pisces, Golden Chollima, and Labyrinth Chollima. Multiple public attributions assess the actor as operating with a DPRK nexus, and some reporting aligns it with North Korea’s Reconnaissance General Bureau under the broader Lazarus ecosystem. AppleJeus is best known for campaigns involving trojanized cryptocurrency trading or wallet-related applications, long-running social engineering against crypto firms and developers, and compromise of trusted software distribution channels. The actor has been linked to the 3CX software supply-chain intrusion disclosed in 2023, which was assessed as North Korea-nexus activity and notable for a cascading supply-chain model in which one upstream compromise enabled another. The group has also been tied to major cryptocurrency theft operations, including the October 2024 Radiant Capital compromise and the April 2026 Drift Protocol theft, both of which involved extended preparation, trust-building, and compromise of signing or administrative workflows rather than exploitation of simple smart contract flaws. Targeting is concentrated on cryptocurrency exchanges, fintech companies, decentralized finance protocols, blockchain developers, and related service providers. AppleJeus has also shown interest in software vendors and supply-chain positions that provide downstream access to high-value victims. Tradecraft repeatedly combines social engineering, fake business relationships, recruitment or partnership lures, malicious code repositories, trojanized applications, and abuse of developer tooling. Reported operations include use of malicious Visual Studio Code project behavior, wallet-themed lures, and software intended to compromise macOS, Windows, and Linux environments. Observed techniques include supply-chain compromise, social engineering, use of fake personas and intermediaries, trojanized software, credential theft, persistence through malicious extensions or backdoors, HTTPS-based command and control, and process injection. In some operations the actor has used malware families and tooling associated with DPRK cryptocurrency theft activity, including backdoors delivered through trading or wallet applications and malware designed to evade transaction review or compromise signer devices. Reporting also links the cluster to exploitation of Chromium zero-day activity under the Citrine Sleet name. AppleJeus appears to prioritize revenue generation for the North Korean state through theft of digital assets while maintaining the operational patience and tradecraft typical of a state-sponsored actor. Its operations demonstrate a blend of espionage-style access development and criminal monetization, with particular strength in abusing trust relationships, developer ecosystems, and governance or signing processes inside cryptocurrency organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
20 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an annotated threat actor associated with the ATT&CK technique Process Injection (T1055) in a Splunk detection entry; no campaign or activity is described.
Mentioned only as an annotation/tag associated with the ATT&CK technique Process Injection (T1055); no campaign or activity by this group is described in the content.
Mentioned only in an annotation/list associated with the detection content; no actor-specific activity is described in this reference.
Listed in annotations alongside ATT&CK technique metadata for the detection; no campaign or activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.