AppleJeus is a family of Windows and macOS malware used by the North Korean state-sponsored Lazarus Group in operations targeting cryptocurrency users, cryptocurrency exchanges, and financial services companies to facilitate cryptocurrency theft. First discovered in August 2018, it has appeared in multiple trojanized trading and wallet applications, including Celas Trade Pro, Kupay Wallet, and Ants2Whale. Distribution uses spearphishing links and websites presenting attacker-controlled software as legitimate cryptocurrency applications. Installation typically requires user execution and may deploy a functional application alongside a malicious updater or helper component.
AppleJeus components collect and exfiltrate host information, communicate with command-and-control servers, and retrieve and execute additional payloads. Windows variants can execute received payloads directly in memory, while a documented macOS second stage supports terminal command execution, file reading and writing, and payload transfer. Persistence mechanisms include Windows services, scheduled tasks running as SYSTEM at user logon, and macOS LaunchDaemons. Defense-evasion behaviors include deleting installation artifacts, hiding macOS property-list files with dot-prefixed names, and decoding or decrypting received data using Base64 and XOR. Windows installation has also requested elevation through a UAC prompt.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The PDB path iqvw64e.pdb is the symbol name for iqvw64e.sys, the Intel Ethernet diagnostics driver — the canonical Bring-Your-Own-Vulnerable-Driver target (CVE-2015-2291), abused by Scattered Spider, BlackByte, and Lazarus/AppleJeus to disable EDR from the kernel. | The vulnerable Intel driver is described as being abused by Scattered Spider, BlackByte, and Lazarus/AppleJeus to disable EDR from the kernel.
During the 3CX Supply Chain Attack, AppleJeus leveraged the Chrome vulnerability, CVE-2022-0609, in combination with a Drive-by Compromise website.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The vulnerable Intel driver is described as being abused by Scattered Spider, BlackByte, and Lazarus/AppleJeus to disable EDR from the kernel.
The adversary’s malware originates with Jeus in 2018 (and its macOS variant, AppleJeus), which originally masqueraded as a cryptocurrency application purportedly developed by the fictitious company Celas Limited.
The joint cybersecurity analysis and MARs highlight the cyber threat North Korea – which is referred to by the U.S. government as HIDDEN COBRA – poses to cryptocurrency and identify malware and indicators of compromise related to the “AppleJeus” family of malware (the name given by the cybersecurity community to a family of North Korean malicious cryptocurrency applications that includes Celas Trade Pro, WorldBit-Bot, Union Crypto Trader, Kupay Wallet, CoinGo Trade, Dorusio, CryptoNeuro Trader, and Ants2Whale).
Citrine Sleet DEV-0139, DEV-1222 North Korea AppleJeus, Labyrinth Chollima, UNC4736
...G1049:AppleJeus turned one trusted dependency into another foothold... From AppleJeus and G1052:Contagious Interview driving cryptocurrency theft...
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails... has required user execution of a malicious MSI installer... has been executed through user installation of an executable disguised as a flash installer.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
387 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
111 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lazarus malware branch specialized in cryptocurrency theft and linked here to the 3CX supply-chain attack.
Annotations ID Technique Tactic T1078 Valid Accounts Initial Access T1098 Account Manipulation Persistence T1548.001 Setuid and Setgid Privilege Escalation Delivery Installation Exploitation APT28 ... Akira ... AppleJeus ...
Annotations ID Technique Tactic T1055 Process Injection Privilege Escalation APT37 APT38 APT41 APT5 AppleJeus BlackByte Cobalt Group Gamaredon Group Kimsuky PLATINUM Sandworm Team Silence TA2541 Turla UNC3886 Velvet Ant Wizard Spider
Annotations ID Technique Tactic T1055 Process Injection Privilege Escalation APT37 APT38 APT41 APT5 AppleJeus BlackByte Cobalt Group...
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.