OAK — OnChain Attack Knowledge

Software · OAK-S12 · malware

OAK-S12 — JADESNOW

Type
malware
Aliases
JADESNOW (Mandiant-original naming, retained as the canonical industry label per the March 2023 APT43 attribution report); related Mandiant-tracked components in the APT43 toolset that JADESNOW operates alongside include LATEOP (initial-access loader), BABYSHARK (PowerShell-based reconnaissance / staging family also documented in Kimsuky activity by multiple vendors), and QUASARRAT customisations attributed to the cluster; the broader Kimsuky / APT43 toolset is tracked under external Group ID G0094 with a software-entry list that overlaps JADESNOW's operational role.
Active
yes (continued use within APT43 / Kimsuky operations through 2024–2025 per Mandiant, Microsoft, and Recorded Future reporting; specific JADESNOW build-versioning is not consolidated in public reporting at the level of detail that AppleJeus or Manuscrypt enjoy).
First observed
2023-03 (Mandiant March 28, 2023 APT43 attribution report public-naming date; underlying tool-development-and-deployment activity dates to earlier within Kimsuky's operational history per Mandiant's longitudinal tracking).
Used by Groups
OAK-G07 (APT43 / Kimsuky — confirmed at the cluster-and-state-attribution level per Mandiant, U.S. Treasury OFAC SDN designation of Kimsuky on November 30, 2023, Republic of Korea MOFA designation of Kimsuky on June 2, 2023, and BfV / NIS joint advisory of March 20, 2023).
Host platforms
Windows (the dominant deployment target for JADESNOW within the APT43 / Kimsuky operational profile, consistent with the cluster's spear-phishing-into-Windows-victim-environment tradecraft against policy researchers, journalists, and government targets).
Observed Techniques
OAK-T8.001 (common-funder cluster reuse — JADESNOW's role in credential-and-wallet-artifact harvesting feeds the post-compromise cluster activity that on-chain forensics tracks under G07's distinctive laundering profile). Pre-incident vectors (spear-phishing with sustained social-engineering rapport-building under fabricated journalist / academic / think-tank personas; malicious browser-extension and Android-app payloads) are out of OAK v0.1 on-chain Tactic scope but are the defining entry surface and are documented at length in the OAK-G07 actor entry.

Description

JADESNOW is a reconnaissance-and-credential-theft Windows backdoor publicly named in Mandiant's March 28, 2023 APT43 attribution report ([mandiantapt432023]) and operationally aligned with the OAK-G07 APT43 / Kimsuky cluster. The family operates as the post-initial-access reconnaissance and credential-and-artifact-harvesting layer in the APT43 toolchain, downstream of LATEOP-family or BABYSHARK-family initial-access loaders and upstream of cluster-distinctive exfiltration patterns (Gmail-and-cloud-data exfiltration via OAuth-token theft and malicious browser extensions; cryptocurrency-wallet-artifact theft; foreign-policy-research-document exfiltration). Mandiant's introduction of the JADESNOW name in the public-record attribution report makes it the canonical industry-naming for this operational role within the APT43 toolset.

Infection vector at the JADESNOW deployment layer is post-initial-access staging — JADESNOW is delivered after a target has already been compromised through APT43 / Kimsuky's defining spear-phishing-with-sustained-social-engineering-rapport entry tradecraft (see OAK-G07 for the full vector profile). The cluster's operators pose as journalists, broadcast writers, foreign-policy researchers, or subject-matter experts and build relationships with targets — diplomats, nuclear-policy researchers, defectors, government officials, journalists covering DPRK affairs — over weeks before delivering payloads. Post-compromise behavior of JADESNOW centers on systematic credential and artifact harvesting: browser-stored credentials, OAuth tokens for Gmail and other cloud services, cryptocurrency-wallet artifacts (MetaMask vault data, Trust Wallet artifacts, related browser-extension wallet data), Korea-specific document files, and reconnaissance data on the victim's professional contacts and organisational position. The harvested data feeds both the cluster's primary espionage mission (foreign-policy intelligence collection) and its self-funding cryptocurrency-theft sub-mission.

The role of JADESNOW in the DPRK financial-funding chain is credential-and-wallet-artifact theft from policy-research and journalist targets who happen to hold cryptocurrency, distinct from the OAK-G01 Lazarus / TraderTraitor model of targeted intrusion against crypto-firm engineering staff for direct extraction. The G01 / G07 distinction at the malware-toolset layer maps onto the broader operational distinction: JADESNOW is part of an espionage-primary toolchain that includes self-funding-secondary capability, while the AppleJeus / TraderTraitor / Manuscrypt lineage is part of a regime-revenue-primary toolchain. Defenders running G01-tuned controls (engineering-staff-focused training, supply-chain build attestation, multisig-vendor diligence) will not catch JADESNOW activity unless those controls also extend to non-engineering staff (policy researchers, communications staff, executive assistants), Gmail / Chrome-extension hardening, and cryptocurrency-wallet-software hardening on staff endpoints.

Observed examples

  • Mandiant APT43 attribution report (March 28, 2023). The public-record introduction of JADESNOW alongside the broader APT43 cluster characterisation, RGB attribution at moderate confidence, hash-rental-and-cloud-mining laundering rail documentation, and >10 million phishing-NFT distribution tracking ([mandiantapt432023]). Confirmed-grade attribution at the cluster-and-state-attribution level per the multi-vendor and multi-government corroborating record.
  • 2024–2025 Kimsuky / APT43 cryptocurrency-credential-harvesting campaigns. Multi-stage VBScript / PowerShell loaders with anti-VM checks and ZIP-compressed exfiltration of browser credentials and cryptocurrency-wallet artifacts (MetaMask, Trust Wallet); industry reporting attributes this campaign cohort to Kimsuky / G07 with JADESNOW or JADESNOW-adjacent tooling implicated in the post-loader stage. Inferred-strong attribution per OAK-G07 actor-entry methodology.
  • Foreign-policy-target cohort across 2023–2025. Sustained cluster activity against diplomats, nuclear-policy researchers, defectors, journalists covering DPRK affairs, and government bodies (Republic of Korea government, U.S. State Department, U.S. Department of Energy historically); per-victim JADESNOW-naming is generally not in public post-mortems but the cluster-level activity is documented across Mandiant, Microsoft, Google TAG, Recorded Future, and Proofpoint reporting.

Detection / attribution signals

  • Spear-phishing-and-rapport-building entry indicators — sustained correspondence-style social-engineering against policy researchers, journalists, and government staff with fabricated journalist / academic / think-tank personas; this is the highest-yield top-of-funnel signal for OAK-G07 activity and is the surface that the BfV / NIS joint advisory of March 20, 2023 specifically calls out.
  • Malicious browser-extension indicators — Chromium-extension Gmail exfiltration as a documented G07-distinctive TTP per [bfvnis2023kimsuky]; defenders should monitor extension-installation events and OAuth-grant patterns on staff Google Workspace / Gmail accounts as a paired control.
  • PowerShell / VBScript loader fingerprints — multi-stage loaders with anti-VM checks, anti-debugging routines, and ZIP-compressed exfiltration of browser-credential and cryptocurrency-wallet-artifact data; the loader-and-final-payload pattern is itself a behavioral fingerprint distinguishable from commodity script-based malware.
  • Wallet-artifact theft fingerprints — file-system access to MetaMask vault paths (%APPDATA%\Local\Google\Chrome\User Data\Default\Local Extension Settings\<MetaMask-extension-ID>), Trust Wallet artifact paths, and related browser-extension-wallet storage; defenders should treat read-access to these paths from non-wallet-software processes as a high-prior signal.
  • Behavioral signatures from CTI vendors — Mandiant (APT43 / JADESNOW rules), Microsoft (Emerald Sleet / Thallium-legacy detection content in Defender for Endpoint), CrowdStrike (Velvet Chollima rules), Google TAG (ARCHIPELAGO detection content), Proofpoint (TA427 / Springtail rules), Kaspersky and Recorded Future (multi-vendor corroborating coverage), AhnLab Security Emergency Response Center (ASEC) for Korea-targeted variants.
  • Cross-correlation with G07 cluster watchlists — wallet-cluster forensics that distinguish G07 activity from G01 activity at the on-chain-laundering-pattern layer (G07's hash-rental-and-cloud-mining laundering rail is distinct from G01's bridge-and-mixer routing); defenders integrating endpoint detection with on-chain G07 watchlists compound their coverage relative to either alone.

Note: omit specific hashes; consume current IOCs from Mandiant's APT43 report and from CTI-vendor feeds.

Citations

  • [mandiantapt432023] — Mandiant, "APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations," March 28, 2023; primary public-record naming of JADESNOW and characterisation of its operational role within the APT43 toolset.
  • [ofac2023kimsuky] — U.S. Department of the Treasury press release JY1938, November 30, 2023, designating Kimsuky and eight DPRK foreign-based agents; cluster-and-state-attribution anchor.
  • [mofakimsuky2023] — Republic of Korea Ministry of Foreign Affairs designation of Kimsuky, June 2, 2023; second-government corroboration.
  • [bfvnis2023kimsuky] — Joint cyber-security advisory by the German Bundesamt für Verfassungsschutz (BfV) and the Republic of Korea National Intelligence Service (NIS), March 20, 2023; Chromium-extension and Android-app TTPs.
  • [chainalysis2024dprk] — DPRK-attributed cryptocurrency-theft scale companion citation; G07 sub-cluster contributes to the aggregate.

Discussion

On lineage and ecosystem position. JADESNOW sits within the APT43 / Kimsuky toolset as the reconnaissance-and-credential-theft layer. It is operationally distinct from — but operationally complementary to — LATEOP (the cluster's initial-access loader), BABYSHARK (PowerShell-based reconnaissance and staging family with broader Kimsuky-coverage history), and the cluster's malicious-browser-extension and Android-app delivery surfaces. Defenders should read JADESNOW as one node in a multi-component toolchain rather than as a stand-alone family; its detection content compounds with detection content for the other APT43 components.

On the G01 / G07 distinction at the toolset layer. JADESNOW is not part of the AppleJeus / TraderTraitor / Manuscrypt lineage — it is a distinct family with distinct code-lineage and distinct operator-cluster ownership (APT43 / Kimsuky rather than Lazarus / APT38 / BlueNoroff). The cluster boundary between G01 and G07 is operationally important precisely because it partitions the DPRK-attributed-crypto-theft attack surface into two distinct defender-control regimes; JADESNOW's role as a G07-distinctive family is part of how OAK preserves that operational distinction. Conflating the two clusters under "DPRK = Lazarus" — the dominant industry framing pre-2023 that the Mandiant APT43 report explicitly broke — under-counts the policy-research and credential-harvesting attack surface.

On attribution caveats. Cluster-level attribution to DPRK / RGB / APT43 / Kimsuky is confirmed (U.S. Treasury OFAC, Republic of Korea MOFA, German BfV, multiple national CERTs, external Group ID G0094, Mandiant moderate-to-high confidence, multi-vendor industry-forensic corroboration). Per-incident attribution that a specific compromise used JADESNOW as the reconnaissance-and-credential-theft layer is in many cases inferred-strong — public post-mortems often document the attribution to APT43 / Kimsuky at cluster level without family-naming the specific Windows backdoor used. Defenders should treat JADESNOW as a near-default expectation in APT43 / Kimsuky-attributed Windows-environment intrusions in the 2023–2025 window and consume detection content accordingly.

On the relationship to the broader OAK-G07 entry. JADESNOW is one of multiple software-axis entries that fall under the OAK-G07 actor entry; future OAK software-axis additions for LATEOP, BABYSHARK, and the cluster's malicious-Chrome-extension family would each warrant their own OAK-Snn entries on the same per-family-identity principle that motivates this entry. The OAK-G07 actor entry itself (rather than this software entry) is the appropriate place to look up cluster-level attribution methodology, the G01 / G07 partition rationale, and the broader TAXONOMY-GAPS for mining-as-laundering-conversion and volume-distributed credential-and-wallet-drain phishing that the cluster's distinctive TTPs surface for future OAK Tactic additions.

Techniques observed (1)

Used by