AppleJeus is a Lazarus Group malware family associated with North Korean financially motivated operations targeting the cryptocurrency sector. First publicly identified in 2018, it has been distributed as trojanized cryptocurrency trading or wallet applications presented through legitimate-looking company branding and websites. Known variants include Celas Trade Pro, Kupay Wallet, CoinGoTrade, and Ants2Whale. Victims have included cryptocurrency exchanges, financial services companies, and individuals involved with digital assets.
AppleJeus commonly delivers a functional-looking Windows or macOS application alongside a hidden updater, helper, or daemon component that performs the malicious activity. On Windows, observed variants have used MSI-based installers, required user execution, and in some cases prompted for elevation during installation. On macOS, observed variants have used DMG installers and post-install scripts to deploy background components. Persistence mechanisms documented for the family include Windows scheduled tasks, Windows services, DLL search order hijacking, and macOS LaunchDaemons or hidden plist-based launch items. During the 3CX supply-chain intrusion, AppleJeus-related tooling was also observed split across multiple DLLs and using DLL search order hijacking via a Windows service to obtain persistence with elevated privileges.
Core AppleJeus behavior includes collecting host information, communicating with command-and-control infrastructure, decoding or decrypting received payloads, and executing follow-on stages in memory or from disk. Some variants exfiltrate collected system information over the command-and-control channel and support additional file operations and command execution in later stages. The malware has also been observed deleting installer artifacts after installation and hiding persistence-related files on macOS by using dot-prefixed filenames to reduce user visibility.
The family is strongly linked to Lazarus tradecraft and broader DPRK cryptocurrency theft operations. AppleJeus campaigns have relied on social engineering and fake cryptocurrency software to gain initial access rather than overt exploitation, and they are notable for blending plausible trading software with modular back-end implants intended to support reconnaissance, persistence, and follow-on theft operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
During the 3CX Supply Chain Attack, AppleJeus leveraged the Chrome vulnerability, CVE-2022-0609, in combination with a Drive-by Compromise website.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
AppleJeus: Analysis of North Korea’s Cryptocurrency Malware.
The adversary’s malware originates with Jeus in 2018 (and its macOS variant, AppleJeus), which originally masqueraded as a cryptocurrency application purportedly developed by the fictitious company Celas Limited.
The joint cybersecurity analysis and MARs highlight the cyber threat North Korea – which is referred to by the U.S. government as HIDDEN COBRA – poses to cryptocurrency and identify malware and indicators of compromise related to the “AppleJeus” family of malware (the name given by the cybersecurity community to a family of North Korean malicious cryptocurrency applications that includes Celas Trade Pro, WorldBit-Bot, Union Crypto Trader, Kupay Wallet, CoinGo Trade, Dorusio, CryptoNeuro Trader, and Ants2Whale).
Citrine Sleet DEV-0139, DEV-1222 North Korea AppleJeus, Labyrinth Chollima, UNC4736
...G1049:AppleJeus turned one trusted dependency into another foothold... From AppleJeus and G1052:Contagious Interview driving cryptocurrency theft...
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Lazarus Group... is targeting individuals and companies, including cryptocurrency exchanges and financial service companies, through the dissemination of cryptocurrency trading applications that have been modified to include malware that facilitates theft of cryptocurrency.
Celas Trade Pro had been recommended to the victim company via a phishing email from a company known as Celas Limited.
Lazarus Group... is targeting individuals and companies, including cryptocurrency exchanges and financial service companies, through the dissemination of cryptocurrency trading applications that have been modified to include malware... an unsuspecting individual downloads a third-party application from a website that appears legitimate.
there is a postinstall script and a plist file which creates a LaunchDaemon to automatically run the Ants2WhaleHelper program.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The installer contains a postinstall script... The postinstall script creates a “DorusioDaemon” folder in the OSX “/Library/Application Support” folder and moves "dorusio_upgrade" to it.
has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails... has required user execution of a malicious MSI installer... has been executed through user installation of an executable disguised as a flash installer.
The installer contains a postinstall script... This script moves the hidden “.com.celastradepro.plist” file from the installer package to the LaunchDaemons folder.
there is a postinstall script and a plist file which creates a LaunchDaemon to automatically run the Ants2WhaleHelper program.
The installer contains a postinstall script... This script moves the hidden “.com.celastradepro.plist” file from the installer package to the LaunchDaemons folder.
there is a postinstall script and a plist file which creates a LaunchDaemon to automatically run the Ants2WhaleHelper program.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
CoinGoTrade placed the plist file (com.coingotrade.pkg.product.plist) in “/Library/LaunchDaemons/.”
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
All important API calls have been base64 encoded and RC4 encrypted which will be decoded and decrypted at run time.
the malware appears to be from a legitimate-looking cryptocurrency trading company and website, whereby an unsuspecting individual downloads a third-party application from a website that appears legitimate.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
This file is hidden because the leading “.” causes it to not be shown to the user if they view the folder in the Finder application.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
the strings from Ants2Whale reveal the C2 hxxp[:]//45.147.231.77:3000... The C2 for this program is hxxps[:]//www[.]qnalytica.com/wp-rss.php.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
386 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
107 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lazarus malware branch specialized in cryptocurrency theft and linked here to the 3CX supply-chain attack.
Annotations ID Technique Tactic T1078 Valid Accounts Initial Access T1098 Account Manipulation Persistence T1548.001 Setuid and Setgid Privilege Escalation Delivery Installation Exploitation APT28 ... Akira ... AppleJeus ...
Annotations ID Technique Tactic T1055 Process Injection Privilege Escalation APT37 APT38 APT41 APT5 AppleJeus BlackByte Cobalt Group Gamaredon Group Kimsuky PLATINUM Sandworm Team Silence TA2541 Turla UNC3886 Velvet Ant Wizard Spider
Annotations ID Technique Tactic T1055 Process Injection Privilege Escalation APT37 APT38 APT41 APT5 AppleJeus BlackByte Cobalt Group...
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.