Lazarus_Group__2018__Operation_AppleJeus.pdf
ID: dd25d6a6-39d8-4b92-94a1-c3fafbd47e04
STIX ID: report--dd25d6a6-39d8-4b92-94a1-c3fafbd47e04
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2018-08-23
Last Modified Date: 2018-08-23
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
### Executive summary
Kaspersky describes Operation "AppleJeus": a supply-chain campaign attributed to the Lazarus APT that trojanized a seemingly legitimate cryptocurrency trading app (Celas Trade Pro) to push Windows and macOS updaters which exfiltrate system info and fetch RC4-encrypted payloads (Fallchill and additional backdoors); the report includes in-depth malware analysis, persistence and loader mechanics, RC4 keys, extensive IOCs (hashes, file paths, domains, IPs), and infrastructure/WHOIS evidence linking the campaign to known Lazarus infrastructure.
