AppleSeed
MITRE ATT&CK: S0622 View on attack.mitre.org
Aliases: JamBog, AppleSeed
- First seen
- 2021-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows, android
- Profile updated
- 2026-07-07 12:37:33
Targeted industries: government-and-public-sector education-and-nonprofits technology-and-telecommunications
Targeted regions: country_code:kr
Context
AppleSeed is a backdoor that has been used by Kimsuky to target South Korean government, academic, and commercial targets since at least 2021.
Detection coverage
- 1 YARA rules
- 643 Sigma rules
Malware & tools used
- JavaScript (attack-pattern)
- PowerShell (attack-pattern)
- Software Packing (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Masquerading (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Process Discovery (attack-pattern)
- Access Token Manipulation (attack-pattern)
- Keylogging (attack-pattern)
- Data from Local System (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- System Information Discovery (attack-pattern)
- Automated Collection (attack-pattern)
- Exfiltration Over Web Service (attack-pattern)
- Data Transfer Size Limits (attack-pattern)
- Native API (attack-pattern)
- Archive Collected Data (attack-pattern)
- Fallback Channels (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Web Protocols (attack-pattern)
- File Deletion (attack-pattern)
- Screen Capture (attack-pattern)
Used by threat actors
- Kimsuky (threat-actor)
Detection rules
- MALPEDIA_Win_Appleseed_Auto (yara-rule)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- blog.malwarebytes.com — Kimsuky Apt Continues To Target South Korean Government Using Appleseed Backdoor (report)
- asec.ahnlab.com — 59590 (report)
- youtube.com — Watch (report)
- genians.co.kr — Triple Combo (report)
- i.blackhat.com — As 21 Kuo We Are About To Land How Clouddragon Turns A Nightmare Into Reality (report)
- medium.com — Kimsuky Disguised As A Korean Company Signed With A Valid Certificate To Distribute Troll Stealer Cfa5D54314E2 (report)
- asec.ahnlab.com — 60054 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Appleseed (report)
- vblocalhost.com — Operation Newton Hi Kimsuky Did An Appleseed Really Fall On Newtons Head (report)
- asec.ahnlab.com — 26705 (report)
- asec.ahnlab.com — 30532 (report)
- asec.ahnlab.com — 36368 (report)
- asec.ahnlab.com — 54804 (report)
- conference.hitb.org — D2T1%20 %20The%20Phishermen%20 %20Dissecting%20Phishing%20Techniques%20Of%20Clouddragon%20Apt%20 %20Linda%20Kuo%20&Zih Cing%20Liao%20 (report)
- youtube.com — Watch (report)
- asec.ahnlab.com — 36918 (report)
- telsy.com — 5654 (report)
- asec.ahnlab.com — Kimsuky %Ea%B7%B8%Eb%A3%B9%Ec%9D%98 Apt %Ea%B3%B5%Ea%B2%A9 %Eb%B6%84%Ec%84%9D %Eb%B3%B4%Ea%B3%A0%Ec%84%9C Appleseed Pebbledash (report)
- asec.ahnlab.com — 41015 (report)
- boho.or.kr — Filedownload.Do (report)
- boho.or.kr — Filedownload.Do (report)
- download.ahnlab.com — Analysis%20Report%20Of%20Kimsuky%20Group (report)
- boho.or.kr — Filedownload.Do (report)
- MITRE ATT&CK — S0622 (report)