MAR-10322463-2.v1 - AppleJeus: JMT Trading
2021-02-17 • USCISA •
CISA, the FBI, and the U.S. Treasury attribute the JMT Trading version of AppleJeus to North Korean state-sponsored Lazarus Group activity targeting cryptocurrency users and businesses. Malicious Windows and macOS installers paired a functioning trading client with a CrashReporter backdoor that established persistence and communicated with `beastgoc.com`. The macOS component could download files and execute shell commands, while the obfuscated Windows version exposed file, registry, payload, and process-management capabilities. The applications were distributed through `jmttrading.org` and a GitHub release repository before the hosted files were replaced with clean installers.