AppleJeus is a North Korea-linked malware family used in cryptocurrency theft operations and associated with Lazarus Group activity. It is best known for masquerading as legitimate cryptocurrency trading or wallet software and has included trojanized applications such as Celas Trade Pro, Union Crypto, Kupay Wallet, CoinGo Trade, Dorusio, and Ants2Whale. The family has targeted cryptocurrency exchanges, financial services firms, decentralized finance organizations, developers, and other victims across multiple countries, with broader victim sectors including energy, government, industry, technology, and telecommunications.
AppleJeus commonly relies on social engineering and user-driven installation of seemingly legitimate software packages, including malicious installers for Windows and macOS. Once executed, variants establish persistence through mechanisms such as Windows services, scheduled tasks, and macOS LaunchDaemons or hidden plist files. The malware has used defense-evasion measures including hidden files on macOS, valid code-signing certificates to appear legitimate, and process injection in later tradecraft associated with the 3CX supply-chain intrusion.
Operationally, AppleJeus performs host profiling, exfiltrates collected system information to command-and-control infrastructure, and retrieves additional payloads for staged execution. Documented capabilities across variants include command execution, file and directory operations, screenshot capture, configuration updates, and in-memory loading of second-stage components. AppleJeus has also been linked to selective follow-on deployment of additional Lazarus tooling in high-value environments.
The malware family has been publicly tied to North Korean efforts to generate illicit revenue and evade sanctions through theft of cryptocurrency. AppleJeus infrastructure and malware characteristics have also been linked to the 3CX supply-chain attack, and reporting has described the AppleJeus branch as specializing in cryptocurrency theft within the broader Lazarus ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
During the 3CX Supply Chain Attack, AppleJeus leveraged the Chrome vulnerability, CVE-2022-0609, in combination with a Drive-by Compromise website.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ветвь AppleJeus специализируется на криптовалютных хищениях и стоит за атакой на цепочку поставок 3CX.
The joint cybersecurity analysis and MARs highlight the cyber threat North Korea – which is referred to by the U.S. government as HIDDEN COBRA – poses to cryptocurrency and identify malware and indicators of compromise related to the “AppleJeus” family of malware (the name given by the cybersecurity community to a family of North Korean malicious cryptocurrency applications that includes Celas Trade Pro, WorldBit-Bot, Union Crypto Trader, Kupay Wallet, CoinGo Trade, Dorusio, CryptoNeuro Trader, and Ants2Whale).
Citrine Sleet DEV-0139, DEV-1222 North Korea AppleJeus, Labyrinth Chollima, UNC4736
...G1049:AppleJeus turned one trusted dependency into another foothold... From AppleJeus and G1052:Contagious Interview driving cryptocurrency theft...
30 distinct techniques documented for this family, organized by ATT&CK tactic.
The email provided a link to the Celas’ website, celasllc[.]com ( Acquire Infrastructure: Domain [T1583.001])... Again, the malware was ... distributed on their website, jmttrading[.]org ( Acquire Infrastructure: Domain [T1583.001]).
This website contained a “Download from GitHub” button, which linked to JMT Trading’s GitHub page ( Acquire Infrastructure: Web Services [T1583.006]).
FALLCHILL typically infects a system as a file dropped by other HIDDEN COBRA malware ( Develop Capabilities: Malware [T1587.001]).
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
Creation and Deployment of Malicious Cryptocurrency Applications : Development of multiple malicious cryptocurrency applications from March 2018 through at least September 2020 – including Celas Trade Pro, WorldBit-Bot, iCryptoFx, Union Crypto Trader, Kupay Wallet, CoinGo Trade, Dorusio, CryptoNeuro Trader, and Ants2Whale – which would provide the North Korean hackers a backdoor into the victims’ computers.
The postinstall script is a sequence of instructions that runs after successfully installing an application ( Command and Scripting Interpreter: Unix Shell [T1059.004]).
The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
Annotations ID Technique Tactic T1055 Process Injection Privilege Escalation
During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.
...the postinstall script launches the Updater program with the CheckUpdate parameter and runs it in the background (Create or Modify System Process: Launch Daemon [T1543.004]).
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
Annotations ID Technique Tactic T1055 Process Injection Privilege Escalation
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
Agent Tesla has created hidden folders. AppleJeus has added a leading . to plist filenames, unlisting them from the Finder app and default Terminal directory listings. APT28 has saved files with hidden file attributes. FIN13 has created hidden files and folders within a compromised Linux system /tmp directory and also used attrib.exe to hide gathered local host information.
Updater.exe ... collects the victim’s host information ( System Owner/User Discovery [T1033]), encrypts the collected information ... and sends information to a C2 website.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Examples include 'AppleJeus's COLDCAT C2 leverages cookie headers to contain data over HTTPS,' 'ChChes ... embeds data within the Cookie HTTP header,' 'GoldMax ... used custom HTTP cookies for C2,' and 'UPPERCUT ... sending error codes in Cookie headers.'
Targeting of Cryptocurrency Companies and Theft of Cryptocurrency : Targeting of hundreds of cryptocurrency companies and the theft of tens of millions of dollars’ worth of cryptocurrency, including $75 million from a Slovenian cryptocurrency company in December 2017; $24.9 million from an Indonesian cryptocurrency company in September 2018; and $11.8 million from a financial services company in New York in August 2020 in which the hackers used the malicious CryptoNeuro Trader application as a backdoor.
133 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
77 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lazarus malware branch specialized in cryptocurrency theft and linked here to the 3CX supply-chain attack.
Annotations ID Technique Tactic T1055 Process Injection Privilege Escalation APT37 APT38 APT41 APT5 AppleJeus BlackByte Cobalt Group Gamaredon Group Kimsuky PLATINUM Sandworm Team Silence TA2541 Turla UNC3886 Velvet Ant Wizard Spider
Annotations ID Technique Tactic T1055 Process Injection Privilege Escalation APT37 APT38 APT41 APT5 AppleJeus BlackByte Cobalt Group...
Annotations ID Technique Tactic T1055 Process Injection Privilege Escalation APT37 APT38 APT41 APT5 AppleJeus BlackByte Cobalt Group ...
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.