Emerging Threat! Exposing JOKERSPY

2023-06-21 Elastic

https://www.elastic.co/kr/security-labs/inital-research-of-jokerspy

Thumbnail for Emerging Threat! Exposing JOKERSPY

Elastic analyzed a REF9134 intrusion at a prominent Japanese cryptocurrency exchange where an adversary used JOKERSPY components on macOS systems. The activity involved the self-signed Swift binary xcc, which checked permissions such as Full Disk Access, Screen Recording, Accessibility, screen lock state, and attempted TCC database manipulation to evade user prompts. A Python backdoor named sh.py loaded configuration from ~/Public/Safari/sar.dat, beaconed to configured C2 infrastructure, gathered host information, and supported commands for shell execution, file upload and download, configuration changes, and Python code execution. The same activity deployed Swiftbelt to /Users/shared/sb for macOS post-exploitation enumeration, suggesting an intrusion chain focused on reconnaissance, permission abuse, and follow-on access within a cryptocurrency target.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 452c832a17436f61ad5f32ee1c97db0… 2023-06-21 2024-04-11
HASH aa951c053baf011d08f3a60a10c1d09… 2023-06-21 2023-07-19
HASH d895075057e491b34b0f8c0392b44e4… 2023-06-21 2023-07-19
HASH 55554944f74096a836b73310bd55d97… 2023-06-21 2023-06-28
DOMAIN app.influmarket.org 2023-06-21 2023-06-28
HASH 8ca86f78f0c73a46f31be366538423e… 2023-06-21 2023-06-21

Related Actors

Related Reports

« Back