s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.applejeus

📛 Threat Title

Malware family: AppleJeus

Category: AppleJeus First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.applejeus`. Printable name: AppleJeus.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain osx.applejeus VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.applejeus

IOC database

Type
domain
Value
osx.applejeus
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-osx.applejeus

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.applejeus

References (1)

Remediations (10)

  • web:attack.mitre.org

    AppleJeus is a family of downloaders initially discovered in 2018 embedded within trojanized cryptocurrency applications. AppleJeus has been used by Lazarus Group, targeting companies in the energy, finance, government, industry, technology, and telecommunications sectors, and several countries including the United States, United Kingdom, South ...

  • web:cve.nohackme.com

    Malware AppleJeus AppleJeus is a family of downloaders initially discovered in 2018 embedded within trojanized cryptocurrency applications. AppleJeus has been used by Lazarus Group, targeting companies in the energy, finance, government, industry, technology, and telecommunications sectors, and several countries including the United States, United Kingdom, South Korea, Australia, Brazil, New ...

  • web:insanecyber.com

    Unmasking Lazarus Group's macOS Malware : Threat Hunting in Operation AppleJeus As threat actors evolve, so too must our ability to detect and counter them. One particular group that has caught the attention of cybersecurity professionals worldwide is North Korea's infamous Lazarus Group.

  • web:misp-galaxy.org

    AppleJeus is a family of downloaders initially discovered in 2018 embedded within trojanized cryptocurrency applications. AppleJeus has been used by Lazarus Group, targeting companies in the energy, finance, government, industry, technology, and telecommunications sectors, and several countries including the United States, United Kingdom, South ...

  • web:support.trellix.com

    Summary Description of Campaign The Lazarus threat group, also known as HIDDEN COBRA, is suspected to be behind the AppleJeus malware family . The malicious software pretends to be a cryptocurrency trading platform, which has been used by the actor since at least 2018. The malware attacks both Windows and Mac operating systems and is distributed via fake websites, phishing, social networking ...

  • web:unit42.paloaltonetworks.com

    We discovered significant similarities with macOS malware used in a previous AppleJeus campaign reported by CISA, orchestrated by the Gleaming Pisces threat actor. The following similarities indicate a shared codebase: Overlapping code structures Identical function names and encryption keys Similar execution flows We named this RAT family PondRAT.

  • web:www.cisa.gov

    The U.S. Government has identified malware and indicators of compromise (IOCs) used by the North Korean government to facilitate cryptocurrency thefts; the cybersecurity community refers to this activity as " AppleJeus ." This report catalogues AppleJeus malware in detail.

  • web:www.malwarebytes.com

    Click Quarantine to remove the found threats. Reboot the system if prompted to complete the removal process. Business remediation How to remove Trojan. AppleJeus with the Malwarebytes Nebula console You can use the Malwarebytes Anti- Malware Nebula console to scan endpoints. Nebula endpoint tasks menu Choose the Scan + Quarantine option.

  • web:www.securityscientist.net

    AppleJeus (G1049) is a North Korean Lazarus Group operation that pioneered the use of fake cryptocurrency applications as malware delivery vehicles, specifically targeting cryptocurrency exchanges, DeFi platforms, and individual traders to steal digital assets for the North Korean regime.

  • web:www.threatdown.com

    Business remediation How to remove Trojan. AppleJeus with the Malwarebytes Nebula console You can use the Malwarebytes Anti- Malware Nebula console to scan endpoints. Nebula endpoint tasks menu Choose the Scan + Quarantine option.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.