AppleJeus: Analysis of North Korea’s Cryptocurrency Malware
2021-02-17 • USCISA •
FBI, CISA, and Treasury assessed that North Korean state-sponsored Lazarus Group/HIDDEN COBRA actors used AppleJeus malware to target cryptocurrency exchanges, financial services firms, and related organizations for theft. The advisory says the operators have posed as legitimate cryptocurrency trading platforms since at least 2018, using trojanized Windows and macOS applications delivered through lookalike websites, phishing, social networking, and social engineering. It lists multiple AppleJeus variants, including Celas Trade Pro, JMT Trading, Union Crypto, Kupay Wallet, CoinGoTrade, Dorusio, and Ants2Whale, and reports targeting across more than 30 countries and sectors such as finance, technology, government, energy, and telecommunications. The activity matters because the modified trading applications provide access to cryptocurrency transaction environments and support North Korea’s broader sanctions-evasion and theft operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 208.91.197.46 | 2018-02-02 | 2026-05-22 |
| DOMAIN | celasllc.com | 2018-08-15 | 2024-03-05 |
| DOMAIN | kupaywallet.com | 2021-02-17 | 2021-02-18 |
| DOMAIN | dorusio.com | 2021-02-17 | 2021-02-18 |
| DOMAIN | ants2whale.com | 2021-02-17 | 2021-02-18 |
| DOMAIN | coingotrade.com | 2020-07-27 | 2021-02-18 |
| DOMAIN | jmttrading.org | 2019-10-12 | 2021-02-18 |
| DOMAIN | beastgoc.com | 2019-10-12 | 2021-02-18 |
| URL | http://cryptoconsortium.github.… | 2021-02-17 | 2021-02-17 |
| DOMAIN | cryptoconsortium.github.io | 2021-02-17 | 2021-02-17 |
| IPv4 | 198.251.83.27 | 2021-02-17 | 2021-02-17 |
| IPv4 | 184.168.221.40 | 2021-02-17 | 2021-02-17 |
| IPv4 | 45.33.2.79 | 2021-02-17 | 2021-02-17 |
| IPv4 | 198.54.117.199 | 2021-02-17 | 2021-02-17 |
| IPv4 | 198.54.114.175 | 2021-02-17 | 2021-02-17 |
| IPv4 | 198.54.117.200 | 2021-02-17 | 2021-02-17 |
| IPv4 | 184.168.221.57 | 2021-02-17 | 2021-02-17 |
| IPv4 | 96.126.123.244 | 2021-02-17 | 2021-02-17 |
| IPv4 | 198.54.114.237 | 2021-02-17 | 2021-02-17 |
| IPv4 | 104.200.67.96 | 2021-02-17 | 2021-02-17 |
| IPv4 | 45.33.23.183 | 2021-02-17 | 2021-02-17 |
| IPv4 | 185.181.104.82 | 2021-02-17 | 2021-02-17 |
| IPv4 | 198.187.29.20 | 2021-02-17 | 2021-02-17 |
| IPv4 | 198.58.118.167 | 2021-02-17 | 2021-02-17 |
| IPv4 | 209.99.64.18 | 2021-02-17 | 2021-02-17 |
| IPv4 | 198.54.117.198 | 2021-02-17 | 2021-02-17 |
| IPv4 | 145.249.106.19 | 2021-02-17 | 2021-02-17 |
| IPv4 | 107.187.66.103 | 2021-02-17 | 2021-02-17 |
| IPv4 | 45.199.63.220 | 2021-02-17 | 2021-02-17 |
| IPv4 | 45.56.79.23 | 2021-02-17 | 2021-02-17 |
| IPv4 | 146.112.61.107 | 2021-02-17 | 2021-02-17 |
| IPv4 | 198.54.117.197 | 2021-02-17 | 2021-02-17 |
| IPv4 | 45.79.19.196 | 2021-02-17 | 2021-02-17 |
| IPv4 | 198.54.115.51 | 2021-02-17 | 2021-02-17 |
| IPv4 | 175.29.32.160 | 2021-02-17 | 2021-02-17 |
| URL | https://www.unioncrypto.vip/dow… | 2019-12-03 | 2021-02-17 |
| IPv4 | 104.168.167.16 | 2019-12-03 | 2021-02-17 |
| IPv4 | 185.142.236.213 | 2018-08-23 | 2021-02-17 |