G1049

2025-08-25 • MITREAppleJeus

AppleJeus is the MITRE ATT&CK designation for a North Korean state-sponsored group attributed to the Reconnaissance General Bureau, associated with the broader Lazarus Group umbrella and assessed to be closely resourced alongside another Democratic People's Republic of Korea-affiliated group tracked as Temp.Hermit. Active since at least 2018, its mission is generating and laundering revenue for the North Korean government, with the cryptocurrency industry as its primary target. The group is most notably responsible for the 2023 3CX supply chain attack, in which it first compromised an end-of-life trading application downloaded and run inside 3CX's network, then modified the Windows and macOS build environments used to distribute 3CX's own software, delivering trojanized installers signed with a code-signing certificate. During that intrusion it used a browser-information-stealing tool, a macOS backdoor launched via a Launch Daemon, a communications module supporting encrypted channels and process injection into browsers, and DLL search-order hijacking for persistence, while exploiting a Chrome vulnerability for drive-by compromise. More broadly, AppleJeus pairs malicious cryptocurrency software with phishing and selectively deploys backdoors against high-value financial targets.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster