AppleSeed is a backdoor associated with the Kimsuky threat group, first observed in the wild in May 2019. It has been used in espionage campaigns targeting South Korean government organizations and scientific and engineering researchers, including Operation Newton. The family primarily targets Windows systems, and an Android variant has also been identified.
AppleSeed supports persistent access, host monitoring, command-and-control communications, and data upload and download. Its Windows functionality includes keylogging, screenshot capture, local data collection, process enumeration, and discovery of host IP addresses and system timestamps. It can compress and encrypt collected data, exfiltrate files through its command-and-control channel, and delete files after transmission. It can maintain a secondary communication channel while the primary channel handles uploads. Some variants use email-based command and control.
Delivery includes malicious email attachments requiring user execution and targeted spearphishing from compromised internal accounts. Observed lures include purported antivirus updates and JavaScript files disguised as PDF documents. Windows execution mechanisms include PowerShell and the signed Regsvr32 utility, while persistence uses Registry RunOnce autostart entries. Evasion techniques include masquerading as security software components, decoding payloads before execution, dynamically resolving APIs, and using a characteristic double-XOR string-decoding routine. Transferred data can be concealed using fake PDF headers and XOR encoding.
The Android variant collects SMS-related data rather than the keylogging and screenshot data associated with Windows variants. It shares the family's double-XOR decoding routine and fake-PDF-header exfiltration format.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
5.3. Privilege Escalation …….. 5.3.1. UACMe …….. 5.3.2. CVE-2021-1675 Vulnerability
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In the process of tracking the attacks of the Kimsuky group, which are still ongoing after the KHNP cyber terror attack, we discovered a piece of malicious code, called ‘AppleSeed’, in the wild... In our analysis, we identified the initial penetration method, the tools used in the attack including AppleSeed...
The Appleseed backdoor is a multi-component backdoor that can take screenshots, log keystrokes, and collect removable media information and specific victim files.
AppleSeed, a backdoor-type malware that was developed and used by the Kimsuky group, was first discovered in 2019 and has been circulating in various structural and functional variations since then.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
188 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
110 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Existing malware family used by Kimsuky, with enhanced versions such as HappyDoor.
A malware family with Dropper and Spy variants. The Dropper downloads additional malware and executes C2 commands, while the Spy variant steals documents, screenshots, keystrokes, USB drive listings, and data from the C:\GPKI directory.
AppleSeed is referenced as a named malware family discussed alongside PebbleDash in Kimsuky campaigns.
Malware payload referenced as being delivered via malicious QR-code spear-phishing infrastructure in the described Kimsuky campaign, enabling post-compromise access and follow-on operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.