AppleJeus: Analysis of North Korea’s Cryptocurrency Malware

2021-02-17 USCISA

https://us-cert.cisa.gov/ncas/alerts/aa21-048a

Thumbnail for AppleJeus: Analysis of North Korea’s Cryptocurrency Malware

FBI, CISA, and Treasury assessed that North Korean state-sponsored Lazarus Group/HIDDEN COBRA actors used AppleJeus malware to target cryptocurrency exchanges, financial services firms, and related organizations for theft. The advisory says the operators have posed as legitimate cryptocurrency trading platforms since at least 2018, using trojanized Windows and macOS applications delivered through lookalike websites, phishing, social networking, and social engineering. It lists multiple AppleJeus variants, including Celas Trade Pro, JMT Trading, Union Crypto, Kupay Wallet, CoinGoTrade, Dorusio, and Ants2Whale, and reports targeting across more than 30 countries and sectors such as finance, technology, government, energy, and telecommunications. The activity matters because the modified trading applications provide access to cryptocurrency transaction environments and support North Korea’s broader sanctions-evasion and theft operations.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 208.91.197.46 2018-02-02 2026-05-22
DOMAIN celasllc.com 2018-08-15 2024-03-05
DOMAIN kupaywallet.com 2021-02-17 2021-02-18
DOMAIN dorusio.com 2021-02-17 2021-02-18
DOMAIN ants2whale.com 2021-02-17 2021-02-18
DOMAIN coingotrade.com 2020-07-27 2021-02-18
DOMAIN jmttrading.org 2019-10-12 2021-02-18
DOMAIN beastgoc.com 2019-10-12 2021-02-18
URL http://cryptoconsortium.github.… 2021-02-17 2021-02-17
DOMAIN cryptoconsortium.github.io 2021-02-17 2021-02-17
IPv4 198.251.83.27 2021-02-17 2021-02-17
IPv4 184.168.221.40 2021-02-17 2021-02-17
IPv4 45.33.2.79 2021-02-17 2021-02-17
IPv4 198.54.117.199 2021-02-17 2021-02-17
IPv4 198.54.114.175 2021-02-17 2021-02-17
IPv4 198.54.117.200 2021-02-17 2021-02-17
IPv4 184.168.221.57 2021-02-17 2021-02-17
IPv4 96.126.123.244 2021-02-17 2021-02-17
IPv4 198.54.114.237 2021-02-17 2021-02-17
IPv4 104.200.67.96 2021-02-17 2021-02-17
IPv4 45.33.23.183 2021-02-17 2021-02-17
IPv4 185.181.104.82 2021-02-17 2021-02-17
IPv4 198.187.29.20 2021-02-17 2021-02-17
IPv4 198.58.118.167 2021-02-17 2021-02-17
IPv4 209.99.64.18 2021-02-17 2021-02-17
IPv4 198.54.117.198 2021-02-17 2021-02-17
IPv4 145.249.106.19 2021-02-17 2021-02-17
IPv4 107.187.66.103 2021-02-17 2021-02-17
IPv4 45.199.63.220 2021-02-17 2021-02-17
IPv4 45.56.79.23 2021-02-17 2021-02-17
IPv4 146.112.61.107 2021-02-17 2021-02-17
IPv4 198.54.117.197 2021-02-17 2021-02-17
IPv4 45.79.19.196 2021-02-17 2021-02-17
IPv4 198.54.115.51 2021-02-17 2021-02-17
IPv4 175.29.32.160 2021-02-17 2021-02-17
URL https://www.unioncrypto.vip/dow… 2019-12-03 2021-02-17
IPv4 104.168.167.16 2019-12-03 2021-02-17
IPv4 185.142.236.213 2018-08-23 2021-02-17

Related Actors

Related Reports

2020-08-26 • 26% Match
#BeagleBoyz #FASTCash2 #T1082 #T1119 #T1090 #T1140 #T1005 #T1070.004 #T1041 #T1113 #T1020 #T1560 #T1115 #T1083 #T1036 #T1027 #T1071 #T1548.003 #T1204 #T1057 #T1059.005 #T1518.001 #T1566.001 #T1547.001 #T1059.001 #T1053 #T1132.001 #T1102 #T1059 #T1199 #T1105 #T1219 #T1055 #T1553.002 #T1552.004 #T1562.001 #T1486 #T1129 #T1489 #T1078 #T1133 #T1053.003 #T1190 #T1203 #T1189 #T1049 #T1098 #T1087 #T1016 #T1070.006 #T1021.001 #T1574.001 #T1217 #T1106 #T1573 #T1095 #T1056 #T1010 #T1021.002 #T1033 #T1569.002 #T1543.003 #T1485 #T1012 #T1110 #T1561.002 #T1202 #T1070.003 #T1565.001 #T1021 #T1505.003 #T1027.005 #T1056.004 #T1218.001 #T1562.003 #T1014 #T1053.004 #T1101 #T1565.002 #T1565.003 #T1562.006
Shares tags: T1041, T1027, T1059 • Same author: USCISA
« Back