AppleSeed is a Windows backdoor associated with the North Korea-linked Kimsuky intrusion set. It has been used in espionage operations targeting South Korean government entities as well as scientific and engineering researchers, and has also appeared in broader Kimsuky intrusion chains involving credential theft, internal access, and follow-on deployment of additional tooling.
AppleSeed provides remote access and host surveillance capabilities including process enumeration, screenshot capture, host data collection, local IP discovery, timestamp collection, file upload and exfiltration over its command-and-control channel, and deletion of files after exfiltration. It supports persistence through a RunOnce registry entry and can execute payloads through PowerShell or by abusing regsvr32. Variants have used dynamically resolved API calls, payload decoding prior to execution, and masquerading by renaming components to resemble legitimate security software. Its communications have been observed using obfuscation such as XOR-based encoding and fake document headers, and some variants support an alternate command-and-control channel when the primary channel is occupied with uploads.
Operationally, AppleSeed has been delivered through malicious email attachments requiring user execution, including spearphishing campaigns and internal phishing using compromised accounts. In Kimsuky operations it has served as a core implant on Windows endpoints, while other tooling such as web shells, reverse shells, and Meterpreter-related payloads were used on servers and Linux systems. Public reporting has also identified an Android variant linked by code and protocol similarities, but the malware family is primarily established as a Windows backdoor. AppleSeed is notable both for its role in long-running Kimsuky espionage activity and for iterative development across variants, including changes to command-and-control methods and supported command parameters.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
5.3. Privilege Escalation …….. 5.3.1. UACMe …….. 5.3.2. CVE-2021-1675 Vulnerability
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In the process of tracking the attacks of the Kimsuky group, which are still ongoing after the KHNP cyber terror attack, we discovered a piece of malicious code, called ‘AppleSeed’, in the wild... In our analysis, we identified the initial penetration method, the tools used in the attack including AppleSeed...
The Appleseed backdoor is a multi-component backdoor that can take screenshots, log keystrokes, and collect removable media information and specific victim files.
AppleSeed, a backdoor-type malware that was developed and used by the Kimsuky group, was first discovered in 2019 and has been circulating in various structural and functional variations since then.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
Through a phishing attack, the Kimsuky group accesses the webmail service by obtaining the information required for a webmail login... they obtained sensitive information such as administrator account and VPN connection and it was possible to enter the internal server.
On Windows Server, when the malware is executed, it self-replicates and is registered in the scheduler.
On a Linux server... the web shell was downloaded from the outside using the CLI command... through the wget and curl commands, execution permission is granted (chmod) and it is executed.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
%ProgramData%\qijWq.rSCKPC.bat (Batch file that decodes the qijWq.rSCKPC.b64 file)
On Windows Server, when the malware is executed, it self-replicates and is registered in the scheduler.
Through a phishing attack, the Kimsuky group accesses the webmail service by obtaining the information required for a webmail login... they obtained sensitive information such as administrator account and VPN connection and it was possible to enter the internal server.
On Windows Server, the attacker created the default account in the administrators group and created a tool after granting privileges.
On a Linux server, after uploading the web shell file to the administrator page using the previously hijacked administrator account, the malware executes additional commands and downloads and executes the reverse shell to maintain the authority to the server.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder. | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce ... HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx ... reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx\0001\Depend /v 1 /d "C:\temp\evil[.]dll"
On Windows Server, when the malware is executed, it self-replicates and is registered in the scheduler.
the DLL file to be executed is injected into the normal process (rundll32.exe) and executed.
Through a phishing attack, the Kimsuky group accesses the webmail service by obtaining the information required for a webmail login... they obtained sensitive information such as administrator account and VPN connection and it was possible to enter the internal server.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder. | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce ... HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx ... reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx\0001\Depend /v 1 /d "C:\temp\evil[.]dll"
BitPaymer has used dynamic API resolution to avoid identifiable strings within the binary, including RegEnumKeyW.
To hide the operation of the malware, it is disguised by using a legitimate file name such as that of Windows Update-related content or a driver name.
the DLL file to be executed is injected into the normal process (rundll32.exe) and executed.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
Through a phishing attack, the Kimsuky group accesses the webmail service by obtaining the information required for a webmail login... they obtained sensitive information such as administrator account and VPN connection and it was possible to enter the internal server.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The attacker used the following shell commands to search for files and directories on the internal server: ls, cd [DIRECTORY], vi ... etc.
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
When infected with a malicious APK, it communicates with the C&C server using the HTTP/S protocol, receives commands, and performs malicious behaviors such as stealing information from the infected device.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
9.2 Non-application layer & non-standard protocol... Reverse Shell - 27.102.114.63:3101 ... final execution shellcode is socket communication.
184 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
108 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Existing malware family used by Kimsuky, with enhanced versions such as HappyDoor.
A malware family with Dropper and Spy variants. The Dropper downloads additional malware and executes C2 commands, while the Spy variant steals documents, screenshots, keystrokes, USB drive listings, and data from the C:\GPKI directory.
AppleSeed is referenced as a named malware family discussed alongside PebbleDash in Kimsuky campaigns.
Malware payload referenced as being delivered via malicious QR-code spear-phishing infrastructure in the described Kimsuky campaign, enabling post-compromise access and follow-on operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.