MAR-10322463-2.v1 - AppleJeus: JMT Trading
2021-02-17 • USCISA •
CISA, the FBI, and the U.S. Treasury attribute the JMT Trading version of AppleJeus to North Korean state-sponsored Lazarus Group activity targeting cryptocurrency users and businesses. Malicious Windows and macOS installers paired a functioning trading client with a CrashReporter backdoor that established persistence and communicated with `beastgoc.com`. The macOS component could download files and execute shell commands, while the obfuscated Windows version exposed file, registry, payload, and process-management capabilities. The applications were distributed through `jmttrading.org` and a GitHub release repository before the hosted files were replaced with clean installers.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 7ea6391c11077a0f2633104193ec086… | 2021-02-17 | 2021-02-18 |
| HASH | 081d1739422bf050755e6af269a7176… | 2021-02-17 | 2021-02-18 |
| DOMAIN | jmttrading.org | 2021-02-17 | 2021-02-18 |
| HASH | e352d6ea4da596abfdf51f617584611… | 2019-10-17 | 2021-02-18 |
| HASH | 9bf8e8ac82b8f7c3707eb12e77f94cd… | 2019-10-17 | 2021-02-18 |
| HASH | 07c38ca1e0370421f74c949507fc0d2… | 2019-10-17 | 2021-02-18 |
| HASH | 4d6078fc1ea6d3cd65c3ceabf659616… | 2019-10-12 | 2021-02-18 |
| DOMAIN | beastgoc.com | 2019-10-12 | 2021-02-18 |
| IPv4 | 198.187.29.20 | 2021-02-17 | 2021-02-17 |
| URL | https://beastgoc.com/grepmonux.… | 2019-10-12 | 2021-02-17 |
| IPv4 | 185.228.83.32 | 2019-10-12 | 2021-02-17 |