AppleJeus

APT / StateG1049
Origin🇰🇵 Coreia do Norte
Techniques (MITRE ATT&CK)2
SourceMITRE ATT&CK
State sponsor: Korea (Democratic People's Republic of)Attribution confidence: 50%Target categories: Government, Private sector
Targeted regions: South Korea · Bangladesh Bank · Sony Pictures Entertainment · United States · Thailand · France · China · Hong Kong · United Kingdom · Guatemala +9
Also known as:APT 38APT-C-26APT38ATK117ATK3AndarielApplewormBeagleBoyzBlack ArtemisBluenoroffBureau 121COPERNICIUMCOVELLITECitrine SleetDEV-0139DEV-1222Dark SeoulDiamond SleetG0032G0082Gleaming PiscesGroup 77Hastati GroupHidden CobraLabyrinth ChollimaLazarus groupMoonstone SleetNICKEL GLADSTONENewRomanic Cyber Army TeamNickel AcademyOperation AppleJeusOperation DarkSeoulOperation GhostSecretOperation TroySapphire SleetStardust ChollimaSubgroup: BluenoroffTA404UNC1720UNC4736Unit 121Whois Hacking TeamZINCZinc

Vexday analysis

AppleJeus é um grupo de ameaça persistente avançada (APT) patrocinado pelo Estado norte-coreano e atribuído ao Reconnaissance General Bureau, atuando sob o guarda-chuva do Lazarus Group junto a outros atores alinhados à RPDC, como o TEMP.hermit. Ativo desde pelo menos 2018, o grupo tem como missão principal a geração e lavagem de receitas para financiar o governo norte-coreano, com foco predominante na indústria de criptomoedas. É notavelmente responsável pelo ataque à cadeia de suprimentos da 3CX. O grupo é rastreado pelo MITRE ATT&CK sob o identificador G1049 e também é conhecido pelos aliases Gleaming Pisces, Citrine Sleet, UNC1720 e UNC4736, com 2 técnicas ATT&CK documentadas.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity7
Impact: High
T1566ENTRYInitial accessPhishingIMPACTImpactFinancial Theft

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 2

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Initial access

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

AppleJeus uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →