AppleJeus
Also tracked as Gleaming Pisces, Citrine Sleet, UNC1720, UNC4736
AppleJeus is a North Korean state-sponsored threat group attributed to the Reconnaissance General Bureau. Associated with the broader Lazarus Group umbrella of actors, AppleJeus has been active since at least 2018 and is closely aligned in resources with TEMP.hermit, another DPRK-affiliated group under the same umbrella. The group’s primary mission is to generate and launder revenue to provide financial support to the government. AppleJeus primarily targets the cryptocurrency industry and is most notably responsible for the 3CX Supply Chain Attack. The group traditionally deploys malicious cryptocurrency software in combination with Phishing. From these compromised environments, it selectively deploys additional backdoors to enable extended operations against high-value financial targets.
- Known attack methods
- 2
- Origin
- North Korea
- First seen
- 2018
- Last seen
- 2023-03
- Source
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, mapped onto the ATT&CK matrix. Each one is a behaviour you can look for in your own logs, and a control you can test.
Reconnaissance
12 techniques
Resource Development
9 techniques
Initial Access
11 techniques · 1 used
Execution
20 techniques
Persistence
22 techniques
Privilege Escalation
13 techniques
Stealth
30 techniques
Defense Impairment
18 techniques
Credential Access
17 techniques
Discovery
34 techniques
Lateral Movement
9 techniques
Collection
17 techniques
Command and Control
18 techniques
Exfiltration
9 techniques
Impact
15 techniques · 1 used