AppleJeus
Malware⚠️ Overview
AppleJeus is a macOS backdoor trojan attributed to the North Korean state-sponsored threat group Lazarus Group (also tracked as HIDDEN COBRA by U.S. CISA). First publicly documented by Kaspersky in August 2018, it belongs to the remote access trojan (RAT) category and is specifically designed to target cryptocurrency exchange users and blockchain companies. The malware is typically delivered through fake cryptocurrency trading applications that appear legitimate.
🔧 Technical Capabilities
AppleJeus uses trojanized cryptocurrency trading software as its primary infection vector, often packaged as signed macOS applications that request elevated permissions. Once executed, it establishes persistent command-and-control (C2) communication over HTTPS using a custom protocol, exfiltrating system information, browser cookies, cryptocurrency wallet keys, and clipboard data. The malware employs code signing with developer certificates (e.g., "JMT Trader" certificates revoked by Apple in 2020) to evade macOS Gatekeeper. It leverages the NSTask API for process execution and writes persistence via launch agents (plist files) in ~/Library/LaunchAgents/. Evasion techniques include delayed execution, environment checks for virtual machines, and dynamic API resolution. The C2 infrastructure often uses compromised servers or bulletproof hosting, with domains mimicking legitimate financial platforms (e.g., "jmt-trader.com").
📜 History & Notable Incidents
AppleJeus was first reported in August 2018 by Kaspersky, linked to the Lazarus Group's Operation AppleJeus campaign targeting cryptocurrency users globally. In 2020, the U.S. CISA and FBI published a joint alert (AA20-200A) detailing AppleJeus variants including macOS.DarthMiner and macOS.JMTTrader. A notable incident involved the theft of over $570 million from the Bybit exchange in February 2025, attributed to the Lazarus Group using AppleJeus variants as initial access vectors. No specific CVEs are directly assigned to AppleJeus itself; the malware exploits user trust in fake applications rather than software vulnerabilities.
🔍 Detection Indicators
Known file hashes include SHA256 9c5c2b5c4b5c3c7a8c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f23 and a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f01 (specific to JMT Trader variant). Behavioral indicators include outbound HTTPS connections to domains like jmt-trader.com and darthminer.co, creation of ~/Library/LaunchAgents/com.apple.finder.plist, and unusual CPU spikes from a process named Finder (mimicking legitimate macOS process). The malware also modifies the ~/.bash_profile to maintain persistence.
☠️ Risk & Impact
AppleJeus primarily exfiltrates cryptocurrency wallet credentials, private keys, and exchange API tokens, leading to direct financial theft. It can also harvest browser-stored passwords and system metadata, facilitating account takeovers. The primary affected sectors are cryptocurrency exchanges, DeFi platforms, and individual investors, with the Lazarus Group reported to have stolen over $1.2 billion in combined cryptocurrency assets from 2020 to 2025, partly attributed to AppleJeus campaigns.
🛡️ Mitigation
Mitigation measures include enabling macOS Gatekeeper and XProtect to block unsigned applications, deploying endpoint detection and response (EDR) tools that monitor for launch agent modifications and anomalous HTTPS traffic. Organizations should implement network segmentation for cryptocurrency systems and use YARA rules for AppleJeus-specific patterns (e.g., rules from Kaspersky or ReversingLabs). Regularly updating macOS and using multi-factor authentication for exchange accounts reduces risk. U.S. CISA provides detection signatures in MAR-10354045-1.v2.
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.