ATT&CKReferencesCISA AppleJeus Feb 2021

CISA AppleJeus Feb 2021

Cybersecurity and Infrastructure Security Agency. (2021, February 21). AppleJeus: Analysis of North Korea’s Cryptocurrency Malware. Retrieved March 1, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples25

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareAppleJeus

AppleJeus has XOR-encrypted collected system information prior to sending to a C2. AppleJeus has also used the open source ADVObfuscation library for its components.

T1041
Exfiltration Over C2 Channel
MalwareAppleJeus

AppleJeus has exfiltrated collected host information to a C2 server.

T1053.005
Scheduled Task
MalwareAppleJeus

AppleJeus has created a scheduled SYSTEM task that runs when a user logs in.

T1059.004
Unix Shell
MalwareAppleJeus

AppleJeus has used shell scripts to execute commands after installation and set persistence mechanisms.

T1070.004
File Deletion
MalwareAppleJeus

AppleJeus has deleted the MSI file after installation.

T1071.001
Web Protocols
MalwareAppleJeus

AppleJeus has sent data to its C2 server via POST requests.

T1082
System Information Discovery
MalwareAppleJeus

AppleJeus has collected the victim host information after infection.

T1140
Deobfuscate/Decode Files or Information
MalwareAppleJeus

AppleJeus has decoded files received from a C2.

T1204.001
Malicious Link
MalwareAppleJeus

AppleJeus's spearphishing links required user interaction to navigate to the malicious website.

T1204.002
Malicious File
MalwareAppleJeus

AppleJeus has required user execution of a malicious MSI installer.

T1218.007
Msiexec
MalwareAppleJeus

AppleJeus has been installed via MSI installer.

T1497.003
Time Based Checks
MalwareAppleJeus

AppleJeus has waited a specified time before downloading a second stage payload.

T1543.003
Windows Service
MalwareFALLCHILL

FALLCHILL has been installed as a Windows service.

T1543.003
Windows Service
MalwareAppleJeus

AppleJeus can install itself as a service.

T1543.004
Launch Daemon
MalwareAppleJeus

AppleJeus has placed a plist file within the LaunchDaemons folder and launched it manually.

T1548.002
Bypass User Account Control
MalwareAppleJeus

AppleJeus has presented the user with a UAC prompt to elevate privileges while installing.

T1553.002
Code Signing
MalwareAppleJeus

AppleJeus has used a valid digital signature from Sectigo to appear legitimate.

T1564.001
Hidden Files and Directories
MalwareAppleJeus

AppleJeus has added a leading . to plist filenames, unlisting them from the Finder app and default Terminal directory listings.

T1566.002
Spearphishing Link
MalwareAppleJeus

AppleJeus has been distributed via spearphishing link.

T1569.001
Launchctl
MalwareAppleJeus

AppleJeus has loaded a plist file using the launchctl command.

T1573.001
Symmetric Cryptography
MalwareFALLCHILL

FALLCHILL encrypts C2 data with RC4 encryption.

T1583.001
Domains
GroupLazarus Group

Lazarus Group has acquired domains related to their campaigns to act as distribution points and C2 channels.

T1583.006
Web Services
GroupLazarus Group

Lazarus Group has hosted malicious downloads on Github.

T1587.001
Malware
GroupLazarus Group

Lazarus Group has developed custom malware for use in their operations.

T1588.004
Digital Certificates
GroupLazarus Group

Lazarus Group has obtained SSL certificates for their C2 domains.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.