MAR-10322463-2.v1 - AppleJeus: JMT Trading

2021-02-17 • USCISA •

https://www.cisa.gov/news-events/analysis-reports/ar21-048b

Thumbnail for MAR-10322463-2.v1 - AppleJeus: JMT Trading

CISA, the FBI, and the U.S. Treasury attribute the JMT Trading version of AppleJeus to North Korean state-sponsored Lazarus Group activity targeting cryptocurrency users and businesses. Malicious Windows and macOS installers paired a functioning trading client with a CrashReporter backdoor that established persistence and communicated with `beastgoc.com`. The macOS component could download files and execute shell commands, while the obfuscated Windows version exposed file, registry, payload, and process-management capabilities. The applications were distributed through `jmttrading.org` and a GitHub release repository before the hosted files were replaced with clean installers.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7ea6391c11077a0f2633104193ec086… 2021-02-17 2021-02-18
HASH 081d1739422bf050755e6af269a7176… 2021-02-17 2021-02-18
DOMAIN jmttrading.org 2021-02-17 2021-02-18
HASH e352d6ea4da596abfdf51f617584611… 2019-10-17 2021-02-18
HASH 9bf8e8ac82b8f7c3707eb12e77f94cd… 2019-10-17 2021-02-18
HASH 07c38ca1e0370421f74c949507fc0d2… 2019-10-17 2021-02-18
HASH 4d6078fc1ea6d3cd65c3ceabf659616… 2019-10-12 2021-02-18
DOMAIN beastgoc.com 2019-10-12 2021-02-18
IPv4 198.187.29.20 2021-02-17 2021-02-17
URL https://beastgoc.com/grepmonux.… 2019-10-12 2021-02-17
IPv4 185.228.83.32 2019-10-12 2021-02-17

Related Actors

Related Reports

« Back