Cybersecurity and Infrastructure Security Agency. (2021, February 21). AppleJeus: Analysis of North Korea’s Cryptocurrency Malware. Retrieved March 1, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareAppleJeus | AppleJeus has XOR-encrypted collected system information prior to sending to a C2. AppleJeus has also used the open source ADVObfuscation library for its components. |
| T1041 Exfiltration Over C2 Channel |
MalwareAppleJeus | AppleJeus has exfiltrated collected host information to a C2 server. |
| T1053.005 Scheduled Task |
MalwareAppleJeus | AppleJeus has created a scheduled SYSTEM task that runs when a user logs in. |
| T1059.004 Unix Shell |
MalwareAppleJeus | AppleJeus has used shell scripts to execute commands after installation and set persistence mechanisms. |
| T1070.004 File Deletion |
MalwareAppleJeus | AppleJeus has deleted the MSI file after installation. |
| T1071.001 Web Protocols |
MalwareAppleJeus | AppleJeus has sent data to its C2 server via |
| T1082 System Information Discovery |
MalwareAppleJeus | AppleJeus has collected the victim host information after infection. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAppleJeus | AppleJeus has decoded files received from a C2. |
| T1204.001 Malicious Link |
MalwareAppleJeus | AppleJeus's spearphishing links required user interaction to navigate to the malicious website. |
| T1204.002 Malicious File |
MalwareAppleJeus | AppleJeus has required user execution of a malicious MSI installer. |
| T1218.007 Msiexec |
MalwareAppleJeus | AppleJeus has been installed via MSI installer. |
| T1497.003 Time Based Checks |
MalwareAppleJeus | AppleJeus has waited a specified time before downloading a second stage payload. |
| T1543.003 Windows Service |
MalwareFALLCHILL | FALLCHILL has been installed as a Windows service. |
| T1543.003 Windows Service |
MalwareAppleJeus | AppleJeus can install itself as a service. |
| T1543.004 Launch Daemon |
MalwareAppleJeus | AppleJeus has placed a plist file within the |
| T1548.002 Bypass User Account Control |
MalwareAppleJeus | AppleJeus has presented the user with a UAC prompt to elevate privileges while installing. |
| T1553.002 Code Signing |
MalwareAppleJeus | AppleJeus has used a valid digital signature from Sectigo to appear legitimate. |
| T1564.001 Hidden Files and Directories |
MalwareAppleJeus | AppleJeus has added a leading |
| T1566.002 Spearphishing Link |
MalwareAppleJeus | AppleJeus has been distributed via spearphishing link. |
| T1569.001 Launchctl |
MalwareAppleJeus | AppleJeus has loaded a plist file using the |
| T1573.001 Symmetric Cryptography |
MalwareFALLCHILL | FALLCHILL encrypts C2 data with RC4 encryption. |
| T1583.001 Domains |
GroupLazarus Group | Lazarus Group has acquired domains related to their campaigns to act as distribution points and C2 channels. |
| T1583.006 Web Services |
GroupLazarus Group | Lazarus Group has hosted malicious downloads on Github. |
| T1587.001 Malware |
GroupLazarus Group | Lazarus Group has developed custom malware for use in their operations. |
| T1588.004 Digital Certificates |
GroupLazarus Group | Lazarus Group has obtained SSL certificates for their C2 domains. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.