Software · OAK-S12 · malware
OAK-S12 — JADESNOW
Description
JADESNOW is a reconnaissance-and-credential-theft Windows backdoor publicly named in Mandiant's March 28, 2023 APT43 attribution report ([mandiantapt432023]) and operationally aligned with the OAK-G07 APT43 / Kimsuky cluster. The family operates as the post-initial-access reconnaissance and credential-and-artifact-harvesting layer in the APT43 toolchain, downstream of LATEOP-family or BABYSHARK-family initial-access loaders and upstream of cluster-distinctive exfiltration patterns (Gmail-and-cloud-data exfiltration via OAuth-token theft and malicious browser extensions; cryptocurrency-wallet-artifact theft; foreign-policy-research-document exfiltration). Mandiant's introduction of the JADESNOW name in the public-record attribution report makes it the canonical industry-naming for this operational role within the APT43 toolset.
Infection vector at the JADESNOW deployment layer is post-initial-access staging — JADESNOW is delivered after a target has already been compromised through APT43 / Kimsuky's defining spear-phishing-with-sustained-social-engineering-rapport entry tradecraft (see OAK-G07 for the full vector profile). The cluster's operators pose as journalists, broadcast writers, foreign-policy researchers, or subject-matter experts and build relationships with targets — diplomats, nuclear-policy researchers, defectors, government officials, journalists covering DPRK affairs — over weeks before delivering payloads. Post-compromise behavior of JADESNOW centers on systematic credential and artifact harvesting: browser-stored credentials, OAuth tokens for Gmail and other cloud services, cryptocurrency-wallet artifacts (MetaMask vault data, Trust Wallet artifacts, related browser-extension wallet data), Korea-specific document files, and reconnaissance data on the victim's professional contacts and organisational position. The harvested data feeds both the cluster's primary espionage mission (foreign-policy intelligence collection) and its self-funding cryptocurrency-theft sub-mission.
The role of JADESNOW in the DPRK financial-funding chain is credential-and-wallet-artifact theft from policy-research and journalist targets who happen to hold cryptocurrency, distinct from the OAK-G01 Lazarus / TraderTraitor model of targeted intrusion against crypto-firm engineering staff for direct extraction. The G01 / G07 distinction at the malware-toolset layer maps onto the broader operational distinction: JADESNOW is part of an espionage-primary toolchain that includes self-funding-secondary capability, while the AppleJeus / TraderTraitor / Manuscrypt lineage is part of a regime-revenue-primary toolchain. Defenders running G01-tuned controls (engineering-staff-focused training, supply-chain build attestation, multisig-vendor diligence) will not catch JADESNOW activity unless those controls also extend to non-engineering staff (policy researchers, communications staff, executive assistants), Gmail / Chrome-extension hardening, and cryptocurrency-wallet-software hardening on staff endpoints.
Observed examples
- Mandiant APT43 attribution report (March 28, 2023). The public-record introduction of JADESNOW alongside the broader APT43 cluster characterisation, RGB attribution at moderate confidence, hash-rental-and-cloud-mining laundering rail documentation, and >10 million phishing-NFT distribution tracking (
[mandiantapt432023]). Confirmed-grade attribution at the cluster-and-state-attribution level per the multi-vendor and multi-government corroborating record. - 2024–2025 Kimsuky / APT43 cryptocurrency-credential-harvesting campaigns. Multi-stage VBScript / PowerShell loaders with anti-VM checks and ZIP-compressed exfiltration of browser credentials and cryptocurrency-wallet artifacts (MetaMask, Trust Wallet); industry reporting attributes this campaign cohort to Kimsuky / G07 with JADESNOW or JADESNOW-adjacent tooling implicated in the post-loader stage. Inferred-strong attribution per OAK-G07 actor-entry methodology.
- Foreign-policy-target cohort across 2023–2025. Sustained cluster activity against diplomats, nuclear-policy researchers, defectors, journalists covering DPRK affairs, and government bodies (Republic of Korea government, U.S. State Department, U.S. Department of Energy historically); per-victim JADESNOW-naming is generally not in public post-mortems but the cluster-level activity is documented across Mandiant, Microsoft, Google TAG, Recorded Future, and Proofpoint reporting.
Detection / attribution signals
- Spear-phishing-and-rapport-building entry indicators — sustained correspondence-style social-engineering against policy researchers, journalists, and government staff with fabricated journalist / academic / think-tank personas; this is the highest-yield top-of-funnel signal for OAK-G07 activity and is the surface that the BfV / NIS joint advisory of March 20, 2023 specifically calls out.
- Malicious browser-extension indicators — Chromium-extension Gmail exfiltration as a documented G07-distinctive TTP per
[bfvnis2023kimsuky]; defenders should monitor extension-installation events and OAuth-grant patterns on staff Google Workspace / Gmail accounts as a paired control. - PowerShell / VBScript loader fingerprints — multi-stage loaders with anti-VM checks, anti-debugging routines, and ZIP-compressed exfiltration of browser-credential and cryptocurrency-wallet-artifact data; the loader-and-final-payload pattern is itself a behavioral fingerprint distinguishable from commodity script-based malware.
- Wallet-artifact theft fingerprints — file-system access to MetaMask vault paths (
%APPDATA%\Local\Google\Chrome\User Data\Default\Local Extension Settings\<MetaMask-extension-ID>), Trust Wallet artifact paths, and related browser-extension-wallet storage; defenders should treat read-access to these paths from non-wallet-software processes as a high-prior signal. - Behavioral signatures from CTI vendors — Mandiant (APT43 / JADESNOW rules), Microsoft (Emerald Sleet / Thallium-legacy detection content in Defender for Endpoint), CrowdStrike (Velvet Chollima rules), Google TAG (ARCHIPELAGO detection content), Proofpoint (TA427 / Springtail rules), Kaspersky and Recorded Future (multi-vendor corroborating coverage), AhnLab Security Emergency Response Center (ASEC) for Korea-targeted variants.
- Cross-correlation with G07 cluster watchlists — wallet-cluster forensics that distinguish G07 activity from G01 activity at the on-chain-laundering-pattern layer (G07's hash-rental-and-cloud-mining laundering rail is distinct from G01's bridge-and-mixer routing); defenders integrating endpoint detection with on-chain G07 watchlists compound their coverage relative to either alone.
Note: omit specific hashes; consume current IOCs from Mandiant's APT43 report and from CTI-vendor feeds.
Citations
[mandiantapt432023]— Mandiant, "APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations," March 28, 2023; primary public-record naming of JADESNOW and characterisation of its operational role within the APT43 toolset.[ofac2023kimsuky]— U.S. Department of the Treasury press release JY1938, November 30, 2023, designating Kimsuky and eight DPRK foreign-based agents; cluster-and-state-attribution anchor.[mofakimsuky2023]— Republic of Korea Ministry of Foreign Affairs designation of Kimsuky, June 2, 2023; second-government corroboration.[bfvnis2023kimsuky]— Joint cyber-security advisory by the German Bundesamt für Verfassungsschutz (BfV) and the Republic of Korea National Intelligence Service (NIS), March 20, 2023; Chromium-extension and Android-app TTPs.[chainalysis2024dprk]— DPRK-attributed cryptocurrency-theft scale companion citation; G07 sub-cluster contributes to the aggregate.
Discussion
On lineage and ecosystem position. JADESNOW sits within the APT43 / Kimsuky toolset as the reconnaissance-and-credential-theft layer. It is operationally distinct from — but operationally complementary to — LATEOP (the cluster's initial-access loader), BABYSHARK (PowerShell-based reconnaissance and staging family with broader Kimsuky-coverage history), and the cluster's malicious-browser-extension and Android-app delivery surfaces. Defenders should read JADESNOW as one node in a multi-component toolchain rather than as a stand-alone family; its detection content compounds with detection content for the other APT43 components.
On the G01 / G07 distinction at the toolset layer. JADESNOW is not part of the AppleJeus / TraderTraitor / Manuscrypt lineage — it is a distinct family with distinct code-lineage and distinct operator-cluster ownership (APT43 / Kimsuky rather than Lazarus / APT38 / BlueNoroff). The cluster boundary between G01 and G07 is operationally important precisely because it partitions the DPRK-attributed-crypto-theft attack surface into two distinct defender-control regimes; JADESNOW's role as a G07-distinctive family is part of how OAK preserves that operational distinction. Conflating the two clusters under "DPRK = Lazarus" — the dominant industry framing pre-2023 that the Mandiant APT43 report explicitly broke — under-counts the policy-research and credential-harvesting attack surface.
On attribution caveats. Cluster-level attribution to DPRK / RGB / APT43 / Kimsuky is confirmed (U.S. Treasury OFAC, Republic of Korea MOFA, German BfV, multiple national CERTs, external Group ID G0094, Mandiant moderate-to-high confidence, multi-vendor industry-forensic corroboration). Per-incident attribution that a specific compromise used JADESNOW as the reconnaissance-and-credential-theft layer is in many cases inferred-strong — public post-mortems often document the attribution to APT43 / Kimsuky at cluster level without family-naming the specific Windows backdoor used. Defenders should treat JADESNOW as a near-default expectation in APT43 / Kimsuky-attributed Windows-environment intrusions in the 2023–2025 window and consume detection content accordingly.
On the relationship to the broader OAK-G07 entry. JADESNOW is one of multiple software-axis entries that fall under the OAK-G07 actor entry; future OAK software-axis additions for LATEOP, BABYSHARK, and the cluster's malicious-Chrome-extension family would each warrant their own OAK-Snn entries on the same per-family-identity principle that motivates this entry. The OAK-G07 actor entry itself (rather than this software entry) is the appropriate place to look up cluster-level attribution methodology, the G01 / G07 partition rationale, and the broader TAXONOMY-GAPS for mining-as-laundering-conversion and volume-distributed credential-and-wallet-drain phishing that the cluster's distinctive TTPs surface for future OAK Tactic additions.