Last seven days
- First activity
- Jul 31, 2026
- Last activity
- Jul 31, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
AppleSeed is a backdoor malware family attributed to the North Korean threat actor Kimsuky.
Profile source: Mallory opens in a new tabAppleSeed
AppleSeed is a backdoor malware family attributed to the North Korean threat actor Kimsuky. It was first discovered in 2019 and has since appeared in multiple structural and functional variants, including at least Dropper and Spy forms, with reporting noting historical evolution up to version 3.0 and more recent observation of version 2.1. AppleSeed has been used extensively in Kimsuky spear-phishing operations and is commonly delivered through malicious email attachments, including droppers in formats such as JSE, PIF, SCR, and EXE; victims are typically induced to execute files disguised as documents or installers, sometimes while a decoy document is opened. AppleSeed has also been observed executing via PowerShell, using JavaScript to launch PowerShell, and calling regsvr32.exe for execution.
Functionally, AppleSeed is a backdoor and information stealer. The Dropper variant downloads additional malware and executes commands received from its C2 server. The Spy variant gathers sensitive information including documents, screenshots, keystrokes, lists of USB drives, and data from the C:\GPKI directory; reporting also states that since 2022 AppleSeed version 2.1 has collected the C:\GPKI directory, which contains digital certificates used by the South Korean government for secure authentication. AppleSeed can automatically collect data from USB drives, keystrokes, and screen images, find and collect data from removable media devices, take screenshots through API calls, stage files in a central location prior to exfiltration, zip and encrypt collected data, split files when size is 0x1000000 bytes or greater, and exfiltrate files over its command-and-control channel. One report also states AppleSeed used email-based C2 communications via SMTP and IMAP.
AppleSeed is closely associated with Kimsuky campaigns targeting primarily South Korean entities. Reporting indicates the AppleSeed cluster mainly targeted government organizations, with broader Kimsuky victimology including South Korean military, corporate, defense, government, healthcare, medical, machinery, and energy sectors, as well as Korean universities, public institutions, and companies. AppleSeed has often been deployed alongside PebbleDash and related tooling, and enhanced derivatives such as HappyDoor have been described as evolving from the AppleSeed cluster with a focus on data exfiltration and GPKI certificate extraction. A noted artifact is the debug path F:\PC_Manager\Utopia_v0.1\bin\AppleSeed.pdb. A reported C2 indicator associated with one AppleSeed sample is peras1[.]n-e[.]kr at 45.58.52[.]104.
Reported operators
The group is also deploying new malware families like HelloDoor and HttpMalice, variants of PebbleDash, and enhanced versions of AppleSeed, such as HappyDoor, which focuses on data exfiltration and GPKI certificate extraction.
AppleSeed, a backdoor-type malware that was developed and used by the Kimsuky group, was first discovered in 2019 and has been circulating in various structural and functional variations since then.
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.