JuiceLedger

First seen
2022-04-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:16:05

Targeted industries: technology-and-telecommunications professional-services

Context

JuiceLedger is a threat actor known for infostealing through their JuiceStealer .NET assembly. They have evolved from spreading fraudulent applications to conducting supply chain attacks, targeting PyPI contributors with phishing campaigns and typosquatting. Their malicious packages contain a code snippet that downloads and executes JuiceStealer, which has evolved to support additional browsers and Discord. Victims of JuiceLedger attacks are advised to reset passwords and report any suspicious activity to [email protected].

Reports & references

  • sentinelone.com — Pypi Phishing Campaign Juiceledger Threat Actor Pivots From Fake Apps To Supply Chain Attacks (report)

External references