REF9134

2023-06-21 • ElasticEmerging Threat! Exposing JOKERSPY

REF9134 is Elastic Security Labs’ name for a macOS intrusion discovered in late May 2023 at a prominent Japanese cryptocurrency exchange. Elastic introduced the designation in June 2023 while investigating activity later associated with the JOKERSPY toolset. The adversary already had access when researchers observed execution of a self-signed Swift binary known as xcc, attempts to replace the macOS Transparency, Consent, and Control database, and deployment of a Python backdoor named sh.py. The backdoor collected host information, executed shell commands and Python code, managed files, and transferred data, while also installing the open-source Swiftbelt enumeration utility. Elastic assessed that initial access most likely involved a malicious or backdoored plugin or third-party dependency. The activity combined trust-control bypass, system discovery, persistent command execution, and targeted collection against a cryptocurrency-sector victim.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster