AppleJeus is a North Korea-linked threat actor and activity cluster associated with cryptocurrency theft, supply-chain compromise, and targeted intrusion operations. It is widely tracked under the aliases Citrine Sleet, Gleaming Pisces, Labyrinth Chollima, and UNC4736, and has been assessed with high confidence as operating with a DPRK nexus and alignment to the Reconnaissance General Bureau. The cluster is part of the broader Lazarus ecosystem and has been tied to financially motivated operations against cryptocurrency exchanges, decentralized finance platforms, blockchain organizations, and related developers, as well as software supply-chain intrusions. AppleJeus became known for campaigns using trojanized cryptocurrency trading applications to compromise victims and steal digital assets. The actor has targeted cryptocurrency and decentralized finance organizations, including developers and engineering personnel, and has also been linked to major software supply-chain activity, most notably the 3CX compromise. Reporting also connects the cluster to high-impact cryptocurrency theft incidents including the Radiant Capital intrusion and the Drift exploit, both involving social engineering and compromise of trusted workflows or signing environments. Observed tradecraft includes initial access through social engineering, phishing, and trojanized software; post-compromise deployment of malware and rootkit tooling; HTTPS-based command and control; use of cookie-header data hiding in command-and-control traffic; process injection; and privilege escalation through kernel-level exploitation. AppleJeus has been associated with the FudModule rootkit, including deployment following exploitation of Chromium and Windows kernel vulnerabilities. The actor has also demonstrated supply-chain tradecraft in which compromise of one trusted software environment is leveraged to reach downstream victims. The cluster’s operations are predominantly financially motivated, especially in support of large-scale cryptocurrency theft, though its tradecraft and infrastructure overlap with broader DPRK state cyber activity. Known aliases include AppleJeus, Citrine Sleet, UNC4736, Gleaming Pisces, and Labyrinth Chollima.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
53 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
On August 19, 2024, Microsoft identified a North Korean threat actor exploiting a Chromium remote-code-execution (RCE) zero-day vulnerability ( CVE-2024-7971 )... Microsoft noted that Citrine Sleet used Chromium exploit to deploy a FudModule rootkit.
The RCE vulnerability was used to deploy a shellcode containing another exploit ( CVE-2024-38106 ) that was used to escape Chromium’s sandbox and deploy the downloaded FudModule rootkit into the memory.
20 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Attributed with medium-to-high confidence to the April 1 exploit of Drift, which drained roughly $285 million from the Solana perps DEX. The group is also described as being behind the $1.5 billion Bybit hack.
Listed as an associated threat actor in the detection annotation for a Linux usermod root UID set analytic; no specific campaign or activity is described in this reference.
Listed as an associated threat actor in detection annotations for Ghostscript exploitation; no specific campaign activity is described in this reference.
Mentioned only as an annotated threat actor associated with the ATT&CK technique Process Injection (T1055) in a Splunk detection entry; no campaign or activity is described.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.