AppleJeus

APT / StateG1049 ↗
Origin🇰🇵 Coreia do Norte
Techniques (MITRE ATT&CK)2
SourceMITRE ATT&CK
State sponsor: Korea (Democratic People's Republic of)Attribution confidence: 50%Target categories: Government, Private sector
Targeted regions: South Korea · Bangladesh Bank · Sony Pictures Entertainment · United States · Thailand · France · China · Hong Kong · United Kingdom · Guatemala +9
Also known as:APT 38APT-C-26APT38ATK117ATK3AndarielApplewormBeagleBoyzBlack ArtemisBluenoroffBureau 121COPERNICIUMCOVELLITECitrine SleetDEV-0139DEV-1222Dark SeoulDiamond SleetG0032G0082Gleaming PiscesGroup 77Hastati GroupHidden CobraLabyrinth ChollimaLazarus groupMoonstone SleetNICKEL GLADSTONENewRomanic Cyber Army TeamNickel AcademyOperation AppleJeusOperation DarkSeoulOperation GhostSecretOperation TroySapphire SleetStardust ChollimaSubgroup: BluenoroffTA404UNC1720UNC4736Unit 121Whois Hacking TeamZINCZinc

About the group

AppleJeus is a North Korean state-sponsored threat group attributed to the Reconnaissance General Bureau. Associated with the broader Lazarus Group umbrella of actors, AppleJeus has been active since at least 2018 and is closely aligned in resources with TEMP.hermit, another DPRK-affiliated group under the same umbrella. The group’s primary mission is to generate and launder revenue to provide financial support to the government. AppleJeus primarily targets the cryptocurrency industry and is most notably responsible for the 3CX Supply Chain Attack. The group traditionally deploys malicious cryptocurrency software in combination with Phishing. From these compromised environments, it selectively deploys additional backdoors to enable extended operations against high-value financial targets.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity7
Impact: High
T1566ENTRYInitial accessPhishingIMPACTImpactFinancial Theft

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 2

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Initial access

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

AppleJeus uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →