Software · OAK-S32 · malware (Windows backdoor / persistent-access remote-access-trojan with HWP-document-borne delivery surface)
OAK-S32 — AppleSeed
Description
AppleSeed is a Windows-based backdoor and persistent-access remote-access-trojan attributed to the DPRK-state-sponsored Kimsuky / APT43 cluster, deployed across South Korean government, defence, academic, and crypto-firm targets via spear-phishing chains from approximately 2019 forward. The canonical references are the continuous-publication body across Cisco Talos, ESET, Mandiant, AhnLab, and KISA / KrCERT/CC that established the family naming and core capability set in 2019–2020 and has tracked per-version evolution through 2024–2025. The family is the principal Kimsuky-cluster persistence tool on the public record and is documented in the broader institutional-attribution architecture established by the OFAC November 2023 Kimsuky designation, the ROK MOFA June 2023 independent sanctions designation, and the joint German-Korean March 2023 advisory ([ofac2023kimsuky], [mofakimsuky2023], [bfvnis2023kimsuky]).
The family's operational role is persistent access plus operator-driven hands-on-keyboard capability and credential-and-document exfiltration — a textbook Windows-backdoor functional profile, but operationally distinguished by its embedding in Kimsuky's spear-phishing-led intrusion architecture and by its HWP-document-borne delivery surface as the defining tradecraft fingerprint. Hangul Word Processor (HWP) is the dominant word-processor file format in South Korean government, academic, and corporate environments — a non-Microsoft-Office regional-software-ecosystem feature with no significant footprint outside the Korean-language target population. Kimsuky's exploitation of the HWP file format as a malware-delivery surface is the principal tradecraft lock-in to Korean-language-target spear-phishing: the operators craft HWP-document lures under Korean-language-content pretexts (government-ministry communiques, academic conference invitations, defence-industry briefings, cryptocurrency-firm regulatory updates), the documents carry exploit-payload or macro-staged downloader content that retrieves the AppleSeed payload, and the regional-software-ecosystem property of HWP makes the delivery surface structurally hard to monitor from non-Korean-side detection vendor coverage.
Post-execution behaviour is the textbook Windows-backdoor surface: persistent C2 channel to operator-controlled infrastructure; operator-driven file-system enumeration, file-upload-and-download, process-enumeration-and-control, keylogging, and screen-capture capability; secondary-payload staging for additional Kimsuky-cluster tooling. The family's role in the OAK-G07 Kimsuky monetization chain is dual: persistent access for cyber-espionage operations (the dominant Kimsuky-cluster operational pattern, with intelligence-collection on South Korean policy, defence, and academic targets the strategic objective) and persistent access for cryptocurrency-theft sub-operations (a smaller but publicly-documented Kimsuky operational pattern, with Mandiant's APT43 designation explicitly documenting cryptocurrency-theft sub-operations funding broader espionage activity per [mandiantapt43_2023]). The dual operational pattern is structurally distinct from the OAK-G01 / OAK-G08 Lazarus / APT38 / BlueNoroff sub-clusters' direct-extraction-from-crypto-industry-firms operational pattern, and structurally distinct from the OAK-G09 Andariel sub-cluster's ransomware-proceeds-fund-espionage operational pattern (see OAK-S25 Discussion); Kimsuky's operational pattern is cyber-espionage-as-primary-with-cryptocurrency-theft-as-secondary-funding-source rather than financially-motivated-as-primary.
Observed examples
- Kimsuky spear-phishing chains targeting South Korean government and defence (2019–2025). AppleSeed documented as the persistent-access tool in continuous Kimsuky-cluster spear-phishing campaigns across Korean-government ministries, defence-industrial-base firms, academic institutions, and cryptocurrency-firm targets per Talos, ESET, Mandiant, AhnLab, and KISA continuous reporting; confirmed-grade aggregate attribution.
- Korean-language HWP-document-borne delivery campaigns (2019–2025). Continuous Kimsuky-cluster campaigns using Korean-language HWP-document lures under government-ministry / academic-conference / defence-industry / cryptocurrency-regulatory pretexts as the AppleSeed-delivery surface; the HWP-document-borne delivery vector is the family's defining tradecraft fingerprint and is documented in essentially all major Talos, ESET, AhnLab, and KISA AppleSeed publications.
- Kimsuky cryptocurrency-firm-targeting sub-campaigns (2021–2025). AppleSeed-staged intrusions against South Korean cryptocurrency-firm targets documented in Mandiant's APT43 cluster-naming consolidation (
[mandiantapt43_2023]) as the principal evidence base for Kimsuky's cryptocurrency-theft sub-operations; the sub-operations fund broader Kimsuky espionage activity rather than constituting standalone financially-motivated campaigns. Confirmed-grade per Mandiant. - Joint German-Korean March 2023 advisory campaign cohort (
[bfvnis2023kimsuky]). Multi-government joint advisory documenting Kimsuky's social-engineering and credential-theft TTPs including the AppleSeed-staged spear-phishing surface; confirmed-grade institutional attribution and third-government corroboration alongside U.S. Treasury OFAC and ROK MOFA designations. - OAK on-chain example surface. No OAK
examples/entry exists for AppleSeed-binary specifically as of v0.1; the OAK angle is the OAK-G07 cluster cryptocurrency-theft-sub-operation laundering tail (T7.001, T7.002, T8.002) downstream of AppleSeed-staged intrusions against cryptocurrency-firm targets, with the per-incident on-chain forensic record narrower than for OAK-G01 / OAK-G08 Lazarus / APT38 sub-clusters because Kimsuky's cryptocurrency-theft volume is a smaller fraction of total Kimsuky operational output than the Lazarus / APT38 sub-clusters' crypto-industry-extraction volume.
Detection / attribution signals
Defenders should treat AppleSeed detection as a host-layer + delivery-channel-layer joint problem with the HWP-document-borne delivery surface as the most-distinctive tradecraft fingerprint:
- Delivery-channel telemetry (the highest-yield top-of-funnel signal) — Korean-language HWP-document attachments under government-ministry / academic-conference / defence-industry / cryptocurrency-regulatory pretexts; suspicious sender-domain patterns mimicking Korean-government and Korean-academic email surfaces; spear-phishing-chain context (operator-cultivated sender-target rapport over days-to-weeks before payload delivery, mirroring the broader Kimsuky-cluster spear-phishing tradecraft documented in the joint German-Korean March 2023 advisory).
- Host-layer process-tree fingerprints — HWP-document-handler parent process spawning child processes performing exploit-payload-execution or macro-staged-downloader sequences; Windows-binary signature with the per-version variants documented across Talos, ESET, Mandiant, AhnLab, and KISA reporting; persistence via Run-key, Service registration, or Scheduled Task registration under naming that mimics legitimate Windows-system tooling.
- Network-layer telemetry — persistent C2 channel egress to operator-controlled infrastructure with periodic heartbeat-and-tasking pattern; operator-controlled C2-domain naming patterns mimicking Korean-government / Korean-academic / Korean-corporate brands; current C2-domain IOCs published in Talos, AhnLab, and KISA reporting and continuously refreshed via Western-side CTI-vendor feeds.
- On-chain-layer signatures (the OAK-relevant signal for cryptocurrency-theft sub-operations) — Kimsuky-cluster cryptocurrency-theft-sub-operation wallet-cluster persistence (OAK-T8.002) is the principal forensic-attribution signature for the operator cohort's financially-motivated sub-operations specifically; downstream routing follows the broader DPRK-cluster T7-Tactic patterns (T7.001 mixer-routed-hop pre-Tornado-Cash-sanctions, T7.002 CEX deposit-address layering as post-2022 default).
- CTI vendor coverage — Cisco Talos (canonical Western-side AppleSeed publications and continuous tracking;
[talosappleseed2021]), ESET (continuous Kimsuky-cluster tracking and AppleSeed analysis;[esetkimsuky2021]), Mandiant (APT43 cluster-naming consolidation and AppleSeed documentation;[mandiantapt43_2023]), AhnLab (canonical Korean-side publications and continuous tracking;[ahnlabappleseed2021]), KISA / KrCERT/CC (canonical Korean-side government CTI reporting), Microsoft Threat Intelligence (Thallium / Emerald Sleet naming and continuous tracking), CrowdStrike (Velvet Chollima naming), Proofpoint (TA406 naming and continuous Kimsuky-cluster reporting).
Note: omit specific file hashes from this entry. Defenders should consume current IOCs from Talos, AhnLab, and KISA published indicator lists and from live Western-side CTI-vendor feeds named above.
Citations
[talosappleseed2021]— Cisco Talos AppleSeed technical publication; canonical Western-side reference for the family. (NEW citation — see summary.)[esetkimsuky2021]— ESET Kimsuky / AppleSeed continuous tracking and analysis. (NEW citation — see summary.)[mandiantapt43_2023]— Mandiant APT43 cluster-naming consolidation, March 2023; documents Kimsuky cryptocurrency-theft sub-operations and AppleSeed family. (Already in citations.bib per OAK-G07 verification.)[ahnlabappleseed2021]— AhnLab AppleSeed technical publication; canonical Korean-side reference paired with Talos. (NEW citation — see summary.)[ofac2023kimsuky]— Treasury OFAC press release JY1938 designating Kimsuky for cyber-enabled intelligence-gathering. (Already in citations.bib per OAK-G07.)[mofakimsuky2023]— ROK MOFA June 2023 independent sanctions designation of Kimsuky. (Already in citations.bib per OAK-G07.)[bfvnis2023kimsuky]— Joint German-Korean March 2023 advisory on Kimsuky social-engineering operations. (Already in citations.bib per OAK-G07.)[chainalysis2024dprk]— DPRK-attributed cryptocurrency-theft and ransom-proceeds aggregate context (also cited in OAK-G01, OAK-S08, OAK-S25, OAK-S29, OAK-S30).
Discussion
On lineage. AppleSeed sits within the broader DPRK Kimsuky / APT43 cluster's Windows-malware lineage, which is operationally distinct from both the macOS-and-cross-platform malware lineage at OAK-S08 / S20 / S21 / S22 / S29 / S30 (OAK-G01 / OAK-G08 sub-clusters) and the Windows-backdoor lineage at OAK-S31 TigerRAT (OAK-G09 Andariel sub-cluster). The cross-DPRK-sub-cluster Windows-backdoor surface — Andariel's TigerRAT (OAK-S31) and Kimsuky's AppleSeed (OAK-S32) — is a useful comparative reference for understanding the operator-cohort-specific tradecraft and target-population specialisation within the broader DPRK Lazarus constellation: Andariel's TigerRAT is delivered via Log4Shell-class public-facing-vulnerability exploitation against U.S. and ROK DIB / energy / healthcare targets; Kimsuky's AppleSeed is delivered via HWP-document-borne spear-phishing against ROK government / academic / defence / crypto-firm targets. The two families occupy structurally distinct Windows-backdoor niches within the same broader DPRK constellation.
On the HWP-document-borne delivery surface as a strategic surface. The HWP file format's regional-software-ecosystem property — dominant in Korean-government / Korean-academic / Korean-corporate environments, near-zero footprint outside the Korean-language target population — is the principal architectural reason AppleSeed's delivery surface is structurally hard to monitor from non-Korean-side detection vendor coverage. Defenders writing Kimsuky / APT43 detection programs should consume Korean-side CTI feeds (AhnLab, KISA, KrCERT/CC) as primary sources rather than relying on Western-side vendor coverage alone; the asymmetry between Korean-side and Western-side detection-rule coverage of the HWP-document-borne delivery surface is a structural detection-coverage gap with material implications for cryptocurrency-firm targets that operate ROK-side offices or that interface with ROK-government regulatory surfaces.
On the Kimsuky operational pattern as cyber-espionage-primary-with-cryptocurrency-theft-secondary. Kimsuky's operational pattern is the third documented DPRK-sub-cluster operational pattern catalogued at OAK v0.1 software entries, alongside the OAK-G01 / OAK-G08 Lazarus / APT38 / BlueNoroff direct-extraction-from-crypto-industry-firms pattern and the OAK-G09 Andariel ransomware-proceeds-fund-espionage pattern. Where the first pattern is financially-motivated-as-primary and the second pattern is financially-motivated-as-funding-mechanism-for-espionage, Kimsuky's pattern is cyber-espionage-as-primary-with-cryptocurrency-theft-as-secondary-funding-source. Mandiant's APT43 cluster-naming consolidation explicitly documents the secondary-funding-source role of Kimsuky's cryptocurrency-theft sub-operations and is the canonical reference for the operational-pattern framing.
On the OAK Software-vs-Group split. OAK-S32 (this entry) is the AppleSeed codebase — the specific Kimsuky-deployed Windows backdoor named across Talos, ESET, Mandiant, AhnLab, and KISA publications. OAK-G07 (already in the v0.1 catalog) is the Kimsuky / APT43 operator cluster — the DPRK-attributed cluster with the conjoined Kimsuky / APT43 naming reflecting Mandiant's March 2023 cluster-naming consolidation. The cardinality is many-to-one in the same idiom as OAK-S25 Maui / OAK-S31 TigerRAT under OAK-G09 Andariel: OAK-G07 has multiple OAK-Sxx entries under it (OAK-S32 AppleSeed and likely additional future entries as further Kimsuky-cluster families are catalogued); each Sxx is a specific codebase and operational role within the cluster's broader tooling inventory.
On ecosystem position. AppleSeed is the persistent-access-and-staging node in the Kimsuky intrusion architecture; downstream from AppleSeed, the chain runs through Kimsuky-cluster terminal-phase activity (intelligence-collection-and-exfiltration in cyber-espionage campaigns; cryptocurrency-theft in financially-motivated sub-operations) and eventually through OAK-T7-Tactic laundering for the cryptocurrency-theft sub-operations. A defender control program targeting AppleSeed at the host-and-delivery-channel-detection layer compounds with on-chain G07 cluster watchlists at the off-ramp layer for cryptocurrency-theft sub-operations specifically; either alone is partial coverage for the financially-motivated sub-operations, and the cyber-espionage-primary operational pattern requires defender controls focused on the intelligence-collection-and-exfiltration phase rather than on the on-chain monetization tail.