AppleJeus
MITRE ATT&CK: S0584 View on attack.mitre.org
Aliases: AppleJeus
- First seen
- 2018-01-01 00:00:00
- Malware type
- downloader, rat, trojan
- Family
- Malware family
- Operating systems
- windows, macos
- Related IoCs
- 1
- Last IoC activity
- 2025-10-08 16:30:46
- Profile updated
- 2026-07-07 12:47:02
Targeted industries: energy-and-utilities financial-services government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:gb country_code:kr country_code:au country_code:br country_code:nz country_code:ru
Context
AppleJeus is a family of downloaders initially discovered in 2018 embedded within trojanized cryptocurrency applications. AppleJeus has been used by Lazarus Group, targeting companies in the energy, finance, government, industry, technology, and telecommunications sectors, and several countries including the United States, United Kingdom, South Korea, Australia, Brazil, New Zealand, and Russia. AppleJeus has been used to distribute the FALLCHILL RAT.
Detection coverage
- 7 YARA rules
- 372 Sigma rules
Malware & tools used
- Deobfuscate/Decode Files or Information (attack-pattern)
- File Deletion (attack-pattern)
- Installer Packages (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Spearphishing Link (attack-pattern)
- Windows Service (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- Launchctl (attack-pattern)
- Web Protocols (attack-pattern)
- Code Signing (attack-pattern)
- Unix Shell (attack-pattern)
- System Information Discovery (attack-pattern)
- Msiexec (attack-pattern)
- Scheduled Task (attack-pattern)
- Bypass User Account Control (attack-pattern)
- Malicious File (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Time Based Checks (attack-pattern)
- Launch Daemon (attack-pattern)
- Malicious Link (attack-pattern)
Used by threat actors
- Lazarus Group (threat-actor)
Detection rules
- MALPEDIA_Win_Applejeus_Auto (yara-rule)
- VOLEXITY_Apt_Malware_Win_Applejeus_Oct22 (yara-rule)
- VOLEXITY_Apt_Malware_Win_Applejeus_B_Oct22 (yara-rule)
- VOLEXITY_Apt_Malware_Win_Applejeus_C_Oct22 (yara-rule)
- VOLEXITY_Apt_Malware_Win_Applejeus_D_Oct22 (yara-rule)
- VOLEXITY_Apt_Delivery_Macro_Lazypine_Jeus_B (yara-rule)
- VOLEXITY_Apt_Delivery_Office_Macro_Lazypine_Jeus (yara-rule)
Reports & references
- CISA — Aa21 048A (report)
- MITRE ATT&CK — S0584 (report)