OAK — OnChain Attack Knowledge

Software · OAK-S09 · malware

OAK-S09 — AppleJeus

Type
malware
Aliases
AppleJeus (Kaspersky-original 2018 naming, retained by CISA / FBI as canonical); UNC4736 (Mandiant operator-cluster designation that runs the AppleJeus toolset alongside related macOS payloads); Citrine Sleet (Microsoft, post-2023 weather-system naming convention); CryptoCore (overlapping but distinct industry naming used by F-Secure / WithSecure for related DPRK macOS activity); BLINDINGCAN, COPPERHEDGE, and INLETDRIFT are CISA / Mandiant naming for components and successor tooling within the broader AppleJeus toolset; "Hidden Cobra" is the legacy U.S.-government umbrella label that subsumes AppleJeus along with other DPRK families.
Active
yes (continuous evolution since 2018; Citrine Sleet / UNC4736 lineage active through 2024–2025 per Mandiant Radiant Capital attribution).
First observed
2018-08 (Kaspersky's original "Operation AppleJeus" report, August 2018, documenting the Celas Trade Pro distribution); CISA / FBI joint advisory AA21-048A of February 17, 2021 ([cisaaa21048a]) is the canonical U.S.-government reference.
Used by Groups
OAK-G01 (Lazarus / DPRK-attributed crypto theft cluster — confirmed via CISA / FBI / Treasury joint advisory and subsequent OFAC actions).
Host platforms
cross-platform (macOS-focused with foundational role in establishing the macOS-targeting DPRK tradecraft; Windows builds distributed in parallel through 2018–2021).
Observed Techniques
OAK-T11.002 (wallet-software distribution compromise — AppleJeus is the foundational case of a trojanized "trading app" delivered to crypto users at scale), OAK-T11.001 (third-party signing/custody-vendor compromise — used as initial-access payload against vendor employees in incidents like Radiant Capital). Pre-incident vectors (drive-by download from impersonated trading-firm websites; direct delivery via fabricated recruiter / counterparty personas) are out of OAK v0.1 on-chain Tactic scope.

Description

AppleJeus is the foundational DPRK-attributed cross-platform crypto-app trojan family. Originally named by Kaspersky in August 2018 in the "Operation AppleJeus" report documenting the Celas Trade Pro distribution, the family established the trojanized-trading-app vector that has defined DPRK-against-crypto-industry intrusion tradecraft for the seven-plus years since. The canonical U.S.-government reference is the joint CISA / FBI / Treasury advisory AA21-048A of February 17, 2021 ([cisaaa21048a]), which catalogued seven distinct AppleJeus campaigns (Celas Trade Pro, JMT Trading, Union Crypto, Kupay Wallet, CoinGoTrade, Dorusio, and Ants2Whale) and established the family's confirmed-grade DPRK / Lazarus attribution.

Infection vector centers on impersonated cryptocurrency-trading firms: operators stand up convincing-looking websites for fabricated trading platforms (or, in some campaigns, legitimately-registered businesses with no actual trading product), invest in marketing and social-media credibility-building, and distribute trojanized macOS and Windows installers as the platform's "official trading client." Post-compromise behavior is staged: the AppleJeus installer drops a backdoor (Fallchill-family or Manuscrypt-family on Windows; Objective-C, later Swift, and most recently Rust-implemented loaders on macOS — the lineage progression that runs through RustBucket and KandyKorn) which establishes persistence, performs reconnaissance, harvests cryptocurrency-wallet artifacts and credentials, and stages second-stage tooling for hands-on-keyboard intrusion. The operational role of AppleJeus in the DPRK financial-funding chain is both end-user wallet-drain at scale (the original Celas Trade Pro / JMT Trading model) and also initial-access into crypto-industry firms via developer / engineer / executive workstations (the post-2022 Citrine Sleet / UNC4736 evolution documented in the Radiant Capital attribution).

AppleJeus is methodologically important as the foundational DPRK macOS-targeting family — it is the precursor to TraderTraitor (OAK-S08), to RustBucket / KandyKorn / SwiftLoader, and to the entire DPRK-against-crypto-industry macOS intrusion tradecraft. Defenders should read AppleJeus as the prototype that the rest of the lineage iterates on, not as an obsolete or sunset family — the lineage continues to be tracked actively under Microsoft's Citrine Sleet and Mandiant's UNC4736 designations.

Observed examples

  • Celas Trade Pro (August 2018). The original AppleJeus campaign — a fabricated cryptocurrency trading platform with both macOS and Windows installers. Notable as the first publicly-documented DPRK macOS malware deployment. Confirmed-grade attribution per Kaspersky's 2018 report and CISA AA21-048A.
  • JMT Trading (October 2019). Open-source-styled trading-app distribution (GitHub-hosted) used as the second canonical AppleJeus campaign; established the open-source-credibility-building variant of the lure pattern. Confirmed-grade per CISA AA21-048A.
  • Union Crypto, Kupay Wallet, CoinGoTrade, Dorusio, Ants2Whale (2019–2020 cohort). Five further campaigns catalogued in the CISA AA21-048A advisory; each ran a distinct fabricated-trading-firm front. Confirmed-grade per the joint advisory.
  • Radiant Capital (September 2024, ~$50M+). Mandiant attribution to UNC4736 / AppleJeus / Citrine Sleet ([mandiantradiant2024]); the macOS-side payload delivered to a Radiant engineer was within the AppleJeus / Citrine Sleet lineage. Inferred-strong attribution at the high-confidence DPRK-nexus level per Mandiant.
  • Citrine Sleet 2024 zero-day exploitation. Microsoft Threat Intelligence reporting (mid-2024) documented Citrine Sleet — the post-2023 Microsoft naming for the AppleJeus / UNC4736 cluster — exploiting a Chromium V8 zero-day to deliver FudModule rootkit as part of crypto-industry-targeting activity. Inferred-strong attribution (multi-vendor corroborated DPRK-nexus).

Detection / attribution signals

  • Trojanized-trading-app indicators — installer packages from cryptocurrency-trading firms with no verifiable corporate history, no audited trading-engine, no regulatory registration, and rapid social-media credibility-construction over weeks-to-months. CISA AA21-048A's published IOCs include domain lists and installer hashes; defenders should consume the live IOC feed from CISA and from CTI vendors rather than transcribe specific values.
  • macOS process-tree fingerprintsInfo.plist bundles claiming to be cryptocurrency-trading software with non-trading-firm developer-team-IDs (or ad-hoc signed); persistence via LaunchDaemons (system-level) or LaunchAgents (user-level) plist files; child processes invoking curl / python3 / osascript with base64-or-hex-encoded staging from memory; the lineage's later evolutions (RustBucket / KandyKorn) shift to Rust-or-Swift implementations and require Yara-rule updates accordingly.
  • Windows process-tree fingerprints — installer dropping a service or Run-key persistence under naming masquerades that mimic legitimate productivity software; subsequent staging of Manuscrypt-family or Fallchill-family backdoors.
  • C2-domain naming patterns — domains mimicking cryptocurrency-trading-firm or wallet-vendor brands; AA21-048A and subsequent CTI-vendor reporting publish indicator-of-compromise lists.
  • Behavioral signatures from CTI vendors — Kaspersky (foundational AppleJeus rules), CISA's published Yara rules in AA21-048A, Microsoft (Citrine Sleet detection rules in Defender for Endpoint), Mandiant (UNC4736 convergence rules), Jamf Threat Labs and SentinelOne (macOS-specific successor-family detections including KandyKorn / RustBucket / Hidden Risk).
  • Cross-correlation with on-chain G01 cluster watchlists — for end-user wallet-drain variants, the post-compromise outflow concentrates into cluster wallets that on-chain forensics (Chainalysis, Elliptic, TRM Labs) attribute to OAK-G01 with high confidence.

Note: specific hashes are not transcribed here; consume the live IOC feed from CISA AA21-048A and from CTI-vendor feeds.

Citations

  • [cisaaa21048a] — CISA / FBI / Treasury joint advisory AA21-048A, February 17, 2021, "AppleJeus: Analysis of North Korea's Cryptocurrency Malware." Primary U.S.-government confirmed-grade anchor for the family.
  • [mandiantradiant2024] — Mandiant attribution of the September 2024 Radiant Capital compromise to UNC4736 / AppleJeus / Citrine Sleet.
  • [chainalysis2024dprk] — DPRK-attributed cryptocurrency-theft scale; aggregate volumes that AppleJeus-lineage activity contributes to.

Discussion

On lineage and ecosystem position. AppleJeus is the prototype DPRK macOS-targeting crypto-trojan family from which the modern lineage (TraderTraitor / RustBucket / KandyKorn / SwiftLoader / Citrine Sleet) descends. The lineage progression preserves operator continuity (UNC4736 / Citrine Sleet) while rotating implementation language (Objective-C → Swift → Rust) and lure-pattern emphasis (impersonated-trading-firm distribution → recruiter-led targeted delivery → mixed-mode). For OAK purposes AppleJeus and TraderTraitor (OAK-S08) are both canonical entries because they represent two distinct vectors — AppleJeus the foundational trojanized-trading-app-at-scale vector, TraderTraitor the targeted-recruiter-delivered vector — even though they share operator continuity and post-2022 toolset overlap.

On attribution caveats. Cluster-level attribution to DPRK / Lazarus is confirmed (CISA / FBI / Treasury / OFAC; multi-vendor corroboration; sustained government attribution since 2018). The naming overlap between AppleJeus (the family), UNC4736 (the operator cluster per Mandiant), and Citrine Sleet (the operator cluster per Microsoft) is a methodological convenience rather than a confused taxonomy — all three labels point to the same DPRK-attributed intrusion set, with naming differences reflecting vendor-internal taxonomy conventions.

On the AppleJeus / TraderTraitor / Manuscrypt distinction. AppleJeus refers specifically to the trojanized-trading-app-and-related-installer family; Manuscrypt (OAK-S10) refers to the Windows-backdoor family that is staged downstream of AppleJeus and other DPRK initial-access payloads; TraderTraitor (OAK-S08) refers to the post-2022 cross-platform recruiter-led-delivery family that builds on the AppleJeus tradecraft. Defenders should treat the three as related-but-distinct entries in the DPRK toolset rather than as synonyms.

On evolution and persistence. AppleJeus has not been sunset — the Citrine Sleet / UNC4736 lineage continues to operate actively, as evidenced by the Radiant Capital attribution and the 2024 Chromium V8 zero-day exploitation. Defenders should treat AppleJeus as a living lineage with ongoing CTI-vendor coverage rather than as a 2018-era family. The seven-plus-year continuity of the lineage is itself attribution-grade evidence — sustained operator continuity at this duration is rare outside state-sponsored intrusion sets and is consistent with the DPRK-attributed framing.

Techniques observed (2)

Used by