AppleJeus

MITRE ATT&CK: S0584 View on attack.mitre.org

Aliases: AppleJeus

First seen
2018-01-01 00:00:00
Malware type
downloader, rat, trojan
Family
Malware family
Operating systems
windows, macos
Related IoCs
1
Last IoC activity
2025-10-08 16:30:46
Profile updated
2026-07-07 12:47:02

Targeted industries: energy-and-utilities financial-services government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:gb country_code:kr country_code:au country_code:br country_code:nz country_code:ru

Context

AppleJeus is a family of downloaders initially discovered in 2018 embedded within trojanized cryptocurrency applications. AppleJeus has been used by Lazarus Group, targeting companies in the energy, finance, government, industry, technology, and telecommunications sectors, and several countries including the United States, United Kingdom, South Korea, Australia, Brazil, New Zealand, and Russia. AppleJeus has been used to distribute the FALLCHILL RAT.

Detection coverage

  • 7 YARA rules
  • 372 Sigma rules

Malware & tools used

  • Deobfuscate/Decode Files or Information (attack-pattern)
  • File Deletion (attack-pattern)
  • Installer Packages (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Windows Service (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • Launchctl (attack-pattern)
  • Web Protocols (attack-pattern)
  • Code Signing (attack-pattern)
  • Unix Shell (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Msiexec (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • Malicious File (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Time Based Checks (attack-pattern)
  • Launch Daemon (attack-pattern)
  • Malicious Link (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Applejeus_Auto (yara-rule)
  • VOLEXITY_Apt_Malware_Win_Applejeus_Oct22 (yara-rule)
  • VOLEXITY_Apt_Malware_Win_Applejeus_B_Oct22 (yara-rule)
  • VOLEXITY_Apt_Malware_Win_Applejeus_C_Oct22 (yara-rule)
  • VOLEXITY_Apt_Malware_Win_Applejeus_D_Oct22 (yara-rule)
  • VOLEXITY_Apt_Delivery_Macro_Lazypine_Jeus_B (yara-rule)
  • VOLEXITY_Apt_Delivery_Office_Macro_Lazypine_Jeus (yara-rule)

Reports & references

  • CISA — Aa21 048A (report)
  • MITRE ATT&CK — S0584 (report)

External references