Emerging Threat! Exposing JOKERSPY
2023-06-21 • Elastic •
https://www.elastic.co/kr/security-labs/inital-research-of-jokerspy
Elastic analyzed a REF9134 intrusion at a prominent Japanese cryptocurrency exchange where an adversary used JOKERSPY components on macOS systems. The activity involved the self-signed Swift binary xcc, which checked permissions such as Full Disk Access, Screen Recording, Accessibility, screen lock state, and attempted TCC database manipulation to evade user prompts. A Python backdoor named sh.py loaded configuration from ~/Public/Safari/sar.dat, beaconed to configured C2 infrastructure, gathered host information, and supported commands for shell execution, file upload and download, configuration changes, and Python code execution. The same activity deployed Swiftbelt to /Users/shared/sb for macOS post-exploitation enumeration, suggesting an intrusion chain focused on reconnaissance, permission abuse, and follow-on access within a cryptocurrency target.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 452c832a17436f61ad5f32ee1c97db0… | 2023-06-21 | 2024-04-11 |
| HASH | aa951c053baf011d08f3a60a10c1d09… | 2023-06-21 | 2023-07-19 |
| HASH | d895075057e491b34b0f8c0392b44e4… | 2023-06-21 | 2023-07-19 |
| HASH | 55554944f74096a836b73310bd55d97… | 2023-06-21 | 2023-06-28 |
| DOMAIN | app.influmarket.org | 2023-06-21 | 2023-06-28 |
| HASH | 8ca86f78f0c73a46f31be366538423e… | 2023-06-21 | 2023-06-21 |