Skip to content

AppleSeed

AppleSeed is a Windows backdoor associated with the North Korea-linked Kimsuky intrusion set.

Profile source: Mallory opens in a new tab

AppleSeed

Family profile

AppleSeed is a Windows backdoor associated with the North Korea-linked Kimsuky intrusion set. It has been used in espionage operations targeting South Korean government entities as well as scientific and engineering researchers, and has also appeared in broader Kimsuky intrusion chains involving credential theft, internal access, and follow-on deployment of additional tooling.

AppleSeed provides remote access and host surveillance capabilities including process enumeration, screenshot capture, host data collection, local IP discovery, timestamp collection, file upload and exfiltration over its command-and-control channel, and deletion of files after exfiltration. It supports persistence through a RunOnce registry entry and can execute payloads through PowerShell or by abusing regsvr32. Variants have used dynamically resolved API calls, payload decoding prior to execution, and masquerading by renaming components to resemble legitimate security software. Its communications have been observed using obfuscation such as XOR-based encoding and fake document headers, and some variants support an alternate command-and-control channel when the primary channel is occupied with uploads.

Operationally, AppleSeed has been delivered through malicious email attachments requiring user execution, including spearphishing campaigns and internal phishing using compromised accounts. In Kimsuky operations it has served as a core implant on Windows endpoints, while other tooling such as web shells, reverse shells, and Meterpreter-related payloads were used on servers and Linux systems. Public reporting has also identified an Android variant linked by code and protocol similarities, but the malware family is primarily established as a Windows backdoor. AppleSeed is notable both for its role in long-running Kimsuky espionage activity and for iterative development across variants, including changes to command-and-control methods and supported command parameters.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Spoofing

Reported operators

Threat actors

4 named in public reporting
Kimsuky

In the process of tracking the attacks of the Kimsuky group, which are still ongoing after the KHNP cyber terror attack, we discovered a piece of malicious code, called ‘AppleSeed’, in the wild... In our analysis, we identified the initial penetration method, the tools used in the attack including AppleSeed...

Andariel

AppleSeed can collect data on a compromised host.

Wassonite

The Appleseed backdoor is a multi-component backdoor that can take screenshots, log keystrokes, and collect removable media information and specific victim files.

SeedpuNK

AppleSeed, a backdoor-type malware that was developed and used by the Kimsuky group, was first discovered in 2019 and has been circulating in various structural and functional variations since then.

Exploited software

Vulnerabilities linked to AppleSeed

1 CVEs

MITRE ATT&CK

AppleSeed in ATT&CK

68 distinct techniques

Techniques

68 techniques
T1059.001 PowerShell T1547.001 Registry Run Keys / Startup Folder T1534 Internal Spearphishing T1132 Data Encoding T1055.001 Dynamic-link Library Injection T1105 Ingress Tool Transfer T1056.001 Keylogging T1083 File and Directory Discovery T1218.010 Regsvr32 T1140 Deobfuscate/Decode Files or Information T1078 Valid Accounts T1505.003 Web Shell T1048 Exfiltration Over Alternative Protocol T1136.001 Local Account T1036 Masquerading T1053 Scheduled Task/Job T1095 Non-Application Layer Protocol T1021 Remote Services T1566.002 Spearphishing Link T1059 Command and Scripting Interpreter T1113 Screen Capture T1190 Exploit Public-Facing Application T1057 Process Discovery T1106 Native API T1070.004 File Deletion T1071.001 Web Protocols T1041 Exfiltration Over C2 Channel T1016 System Network Configuration Discovery T1005 Data from Local System T1082 System Information Discovery T1008 Fallback Channels T1204 User Execution T1027 Obfuscated Files or Information T1124 System Time Discovery T1059.003 Windows Command Shell T1071 Application Layer Protocol T1021.001 Remote Desktop Protocol T1649 Steal or Forge Authentication Certificates T1204.002 Malicious File T1566 Phishing T1059.005 Visual Basic T1046 Network Service Discovery T1218.005 Mshta T1566.001 Spearphishing Attachment T1007 System Service Discovery T1059.007 JavaScript T1567 Exfiltration Over Web Service T1219 Remote Access Tools T1560 Archive Collected Data T1136 Create Account T1566.003 Spearphishing via Service T1497 Virtualization/Sandbox Evasion T1555 Credentials from Password Stores T1053.005 Scheduled Task T1195 Supply Chain Compromise T1030 Data Transfer Size Limits T1025 Data from Removable Media T1119 Automated Collection T1120 Peripheral Device Discovery T1074 Data Staged T1518.001 Security Software Discovery T1027.002 Software Packing T1087.001 Local Account T1112 Modify Registry T1036.005 Match Legitimate Resource Name or Location T1134 Access Token Manipulation T1074.001 Local Data Staging T1560.001 Archive via Utility

Reporting

Research mentioning AppleSeed

Aug 11
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.

May 13
Splunk Research

Detection: Cmdline Tool Not Executed In CMD Shell | Splunk Security Content

Jan 22
Ahnlab Asec

RID Hijacking Technique Utilized by Andariel Attack Group - ASEC

North Korea-aligned Andariel, a subgroup linked to Lazarus, conducted multiple intrusion campaigns against South Korean organizations across manufacturing, construction, education, defense, telecommunications, semiconductor, shipbuilding, electronics, and ICT sectors. Reporting from AhnLab ties the activity together through recurring victimology, repeated abuse of vulnerable or trusted enterprise software such as INNORIX Agent, domestic asset-management tools, software update mechanisms, and in one case an outdated Apache Tomcat web server. The campaigns also showed likely spearphishing, use of hidden accounts and scheduled tasks for persistence, and credential theft followed by lateral movement and remote desktop access. The operators deployed an evolving malware set that included Goat RAT, AndarLoader, DurianBeacon, Nestdoor, Dora RAT, SmallTiger, TigerRat, NukeSped variants, Black RAT, Lilith RAT, and supporting tools such as PrintSpoofer, Mimikatz, ProcDump, Meterpreter, proxy utilities, keyloggers, clipboard stealers, and browser credential theft tools. AhnLab reported overlaps in command-and-control infrastructure and malware staging, including DurianBeacon delivering AndarLoader, SmallTiger fetching payloads in memory, and some Dora RAT samples being disguised as legitimate software like OpenVPN and signed with valid certificates. The activity reflects a continued shift in Andariel tooling while preserving long-standing tradecraft associated with Lazarus operations.

May 27
Ahnlab Asec

국내 기업 대상 공격에 사용 중인 SmallTiger 악성코드 (Kimsuky, Andariel 그룹) - ASEC

May 16
Ahnlab Asec

Dora RAT을 이용한 국내 기업 대상 APT 공격 사례 분석 (Andariel 그룹) - ASEC

Nov 10
Ahnlab Asec

자산 관리 프로그램을 악용한 공격 정황 포착 (Andariel 그룹) - ASEC

Aug 22
Ahnlab Asec

Andariel 그룹의 새로운 공격 활동 분석 - ASEC

Aug 18
Cyble Blog Historic

Cyble - BianLian: New Ransomware Variant On The Rise

BianLian emerged as a Go-based ransomware family targeting organizations in manufacturing, education, healthcare, and BFSI, with victims reporting file encryption and double-extortion threats. The malware appends the .bianlian extension to encrypted files, drops a ransom note named "Look at this instruction.txt", and warns that allegedly stolen financial, client, business, technical, and personal data will be leaked within ten days unless payment is made through negotiations conducted over TOX Messenger and a Tor-based leak site. Technical analysis shows the malware was built to hinder detection and speed impact on victim systems. BianLian performs anti-analysis checks associated with MITRE ATT&CK T1497 virtualization and sandbox evasion, creates multiple threads to accelerate encryption, enumerates drives from A: through Z:, excludes selected files and folders from encryption, and deletes itself after execution. Its behavior also aligns with broader defense-evasion patterns such as executable obfuscation and packing captured in MITRE ATT&CK T1027.002, underscoring how the ransomware combines rapid file encryption with techniques intended to frustrate automated analysis and reverse engineering.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.