TF-MAL-osx.applejeus
📛 Threat Title
Malware family: AppleJeus
Description
ThreatFox malware family `osx.applejeus`. Printable name: AppleJeus.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.applejeus
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.applejeus
IOC database
- Type
- domain
- Value
osx.applejeus- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.applejeus
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.applejeus
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
AppleJeus is a family of downloaders initially discovered in 2018 embedded within trojanized cryptocurrency applications. AppleJeus has been used by Lazarus Group, targeting companies in the energy, finance, government, industry, technology, and telecommunications sectors, and several countries including the United States, United Kingdom, South ...
-
web:cve.nohackme.com
Malware AppleJeus AppleJeus is a family of downloaders initially discovered in 2018 embedded within trojanized cryptocurrency applications. AppleJeus has been used by Lazarus Group, targeting companies in the energy, finance, government, industry, technology, and telecommunications sectors, and several countries including the United States, United Kingdom, South Korea, Australia, Brazil, New ...
-
web:insanecyber.com
Unmasking Lazarus Group's macOS Malware : Threat Hunting in Operation AppleJeus As threat actors evolve, so too must our ability to detect and counter them. One particular group that has caught the attention of cybersecurity professionals worldwide is North Korea's infamous Lazarus Group.
-
web:misp-galaxy.org
AppleJeus is a family of downloaders initially discovered in 2018 embedded within trojanized cryptocurrency applications. AppleJeus has been used by Lazarus Group, targeting companies in the energy, finance, government, industry, technology, and telecommunications sectors, and several countries including the United States, United Kingdom, South ...
-
web:support.trellix.com
Summary Description of Campaign The Lazarus threat group, also known as HIDDEN COBRA, is suspected to be behind the AppleJeus malware family . The malicious software pretends to be a cryptocurrency trading platform, which has been used by the actor since at least 2018. The malware attacks both Windows and Mac operating systems and is distributed via fake websites, phishing, social networking ...
-
web:unit42.paloaltonetworks.com
We discovered significant similarities with macOS malware used in a previous AppleJeus campaign reported by CISA, orchestrated by the Gleaming Pisces threat actor. The following similarities indicate a shared codebase: Overlapping code structures Identical function names and encryption keys Similar execution flows We named this RAT family PondRAT.
-
web:www.cisa.gov
The U.S. Government has identified malware and indicators of compromise (IOCs) used by the North Korean government to facilitate cryptocurrency thefts; the cybersecurity community refers to this activity as " AppleJeus ." This report catalogues AppleJeus malware in detail.
-
web:www.malwarebytes.com
Click Quarantine to remove the found threats. Reboot the system if prompted to complete the removal process. Business remediation How to remove Trojan. AppleJeus with the Malwarebytes Nebula console You can use the Malwarebytes Anti- Malware Nebula console to scan endpoints. Nebula endpoint tasks menu Choose the Scan + Quarantine option.
-
web:www.securityscientist.net
AppleJeus (G1049) is a North Korean Lazarus Group operation that pioneered the use of fake cryptocurrency applications as malware delivery vehicles, specifically targeting cryptocurrency exchanges, DeFi platforms, and individual traders to steal digital assets for the North Korean regime.
-
web:www.threatdown.com
Business remediation How to remove Trojan. AppleJeus with the Malwarebytes Nebula console You can use the Malwarebytes Anti- Malware Nebula console to scan endpoints. Nebula endpoint tasks menu Choose the Scan + Quarantine option.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.