AppleSeed

MITRE ATT&CK: S0622 View on attack.mitre.org

Aliases: JamBog, AppleSeed

First seen
2021-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows, android
Profile updated
2026-07-07 12:37:33

Targeted industries: government-and-public-sector education-and-nonprofits technology-and-telecommunications

Targeted regions: country_code:kr

Context

AppleSeed is a backdoor that has been used by Kimsuky to target South Korean government, academic, and commercial targets since at least 2021.

Detection coverage

  • 1 YARA rules
  • 643 Sigma rules

Malware & tools used

  • JavaScript (attack-pattern)
  • PowerShell (attack-pattern)
  • Software Packing (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Masquerading (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Process Discovery (attack-pattern)
  • Access Token Manipulation (attack-pattern)
  • Keylogging (attack-pattern)
  • Data from Local System (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Automated Collection (attack-pattern)
  • Exfiltration Over Web Service (attack-pattern)
  • Data Transfer Size Limits (attack-pattern)
  • Native API (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Fallback Channels (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Web Protocols (attack-pattern)
  • File Deletion (attack-pattern)
  • Screen Capture (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Appleseed_Auto (yara-rule)

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • blog.malwarebytes.com — Kimsuky Apt Continues To Target South Korean Government Using Appleseed Backdoor (report)
  • asec.ahnlab.com — 59590 (report)
  • youtube.com — Watch (report)
  • genians.co.kr — Triple Combo (report)
  • i.blackhat.com — As 21 Kuo We Are About To Land How Clouddragon Turns A Nightmare Into Reality (report)
  • medium.com — Kimsuky Disguised As A Korean Company Signed With A Valid Certificate To Distribute Troll Stealer Cfa5D54314E2 (report)
  • asec.ahnlab.com — 60054 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Appleseed (report)
  • vblocalhost.com — Operation Newton Hi Kimsuky Did An Appleseed Really Fall On Newtons Head (report)
  • asec.ahnlab.com — 26705 (report)
  • asec.ahnlab.com — 30532 (report)
  • asec.ahnlab.com — 36368 (report)
  • asec.ahnlab.com — 54804 (report)
  • conference.hitb.org — D2T1%20 %20The%20Phishermen%20 %20Dissecting%20Phishing%20Techniques%20Of%20Clouddragon%20Apt%20 %20Linda%20Kuo%20&Zih Cing%20Liao%20 (report)
  • youtube.com — Watch (report)
  • asec.ahnlab.com — 36918 (report)
  • telsy.com — 5654 (report)
  • asec.ahnlab.com — Kimsuky %Ea%B7%B8%Eb%A3%B9%Ec%9D%98 Apt %Ea%B3%B5%Ea%B2%A9 %Eb%B6%84%Ec%84%9D %Eb%B3%B4%Ea%B3%A0%Ec%84%9C Appleseed Pebbledash (report)
  • asec.ahnlab.com — 41015 (report)
  • boho.or.kr — Filedownload.Do (report)
  • boho.or.kr — Filedownload.Do (report)
  • download.ahnlab.com — Analysis%20Report%20Of%20Kimsuky%20Group (report)
  • boho.or.kr — Filedownload.Do (report)
  • MITRE ATT&CK — S0622 (report)

External references