REF9134
2023-06-21 • Elastic • Emerging Threat! Exposing JOKERSPY
REF9134 is Elastic Security Labs’ name for a macOS intrusion discovered in late May 2023 at a prominent Japanese cryptocurrency exchange. Elastic introduced the designation in June 2023 while investigating activity later associated with the JOKERSPY toolset. The adversary already had access when researchers observed execution of a self-signed Swift binary known as xcc, attempts to replace the macOS Transparency, Consent, and Control database, and deployment of a Python backdoor named sh.py. The backdoor collected host information, executed shell commands and Python code, managed files, and transferred data, while also installing the open-source Swiftbelt enumeration utility. Elastic assessed that initial access most likely involved a malicious or backdoored plugin or third-party dependency. The activity combined trust-control bypass, system discovery, persistent command execution, and targeted collection against a cryptocurrency-sector victim.
-
60
Related Actors
-
1
Related Reports