Malware Analysis – AppleJeus: Ants2Whale

Fortify Security Team
Feb 18, 2021

This Malware Analysis Report (MAR) is the result of analytic efforts among the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Treasury (Treasury) to highlight the cyber threat to cryptocurrency posed by North Korea, formally known as the Democratic People’s Republic of Korea (DPRK), and provide mitigation recommendations. Working with U.S. government partners, FBI, CISA, and Treasury assess that Lazarus Group—which these agencies attribute to North Korean state-sponsored advanced persistent threat (APT) actors—is targeting individuals and companies, including cryptocurrency exchanges and financial service companies, through the dissemination of cryptocurrency trading applications that have been modified to include malware that facilitates theft of cryptocurrency.

This MAR highlights this cyber threat posed by North Korea and provides detailed indicators of compromise (IOCs) used by the North Korean government. The U.S. Government refers to malicious cyber activity by the North Korean government as HIDDEN COBRA. For more information on other versions of AppleJeus and recommended steps to mitigate this threat, see Joint Cybersecurity Advisory AA21-048A: AppleJeus: Analysis of North Korea’s Cryptocurrency Malware at

There have been multiple versions of AppleJeus malware discovered since its initial discovery in August 2018. In most versions, the malware appears to be from a legitimate-looking cryptocurrency trading company and website, whereby an unsuspecting individual downloads a third-party application from a website that appears legitimate.

The U.S. Government has identified AppleJeus malware version—Ants2Whale—and associated IOCs used by the North Korean government in AppleJeus operations.

Ants2Whale, discovered in October 2020, is a legitimate-looking cryptocurrency trading software that is marketed and distributed by a company and website—Ants2Whale and ants2whale[.]com, respectively—that appear legitimate. Some information has been redacted from this report to preserve victim anonymity.

For a downloadable copy of IOCs, see: MAR-10322463-7.v1.stix.

Submitted Files (3)

bb430087484c1f4587c54efc75681eb60cf70956ef2a999a75ce7b563b8bd694 (Ants2WhaleHelper)

d5ac680e14b013e0624470da7f46e84809d00b59a7544f6a42b110cf0e29254e (Ants2Whale)

[Redacted] (Ants2Whale.dmg)

Domains (2)

IPs (1)





Name Ants2Whale.dmg
Size [Redacted] bytes
Type zlib compressed data
MD5 [Redacted]
SHA1 [Redacted]
SHA256 [Redacted]
SHA512 [Redacted]
ssdeep [Redacted]
Entropy [Redacted]
Avira OSX/Agent.denpi
Ikarus OSX.Agent
Zillya! Downloader.Agent.OSX.390
[Redacted] Downloaded_By
[Redacted] Contains d5ac680e14b013e0624470da7f46e84809d00b59a7544f6a42b110cf0e29254e
[Redacted] Contains bb430087484c1f4587c54efc75681eb60cf70956ef2a999a75ce7b563b8bd694

This OSX program from the Ants2Whale site is an Apple DMG installer. The OSX program does not have a digital signature and will warn the user of that before installation. As all previous versions of AppleJeus, the Ants2Whale installer appears to be legitimate and installs “Ants2Whale”(D5AC680E14B013E0624470DA7F46E84809D00B59A7544F6A42B110CF0E29254E) in the “/Applications/” folder and a program named Ants2WhaleHelper (BB430087484C1F4587C54EFC75681EB60CF70956EF2A999A75CE7B563B8BD694) also in the “/Library/Application\ Support/Ants2WhaleSupport/” folder.

Similar to all previous OSX AppleJeus variants, there is a postinstall script and a plist file which creates a LaunchDaemon to automatically run the Ants2WhaleHelper program.

Relationships Downloaded [Redacted]

The website appears to show a legitimate cryptocurrency company and application, though it does contain multiple spelling and grammar mistakes indicating the creator may not have English as a first language. The website states that in order to download, a user must contact the administrator as their product is “premium package.”

The domain had a legitimately signed Sectigo Secure Sockets Layer (SSL) certificate, which was “Domain Control Validated” just as all previous AppleJeus domain certificates. The certificate was is valid from 09/21/2020 – 09/21/2021.

The domain is registered with NameCheap at the IP address with ASN 22612. This IP is on the same ASN as the CoinGoTrade (AppleJeus variant 5 and Dorusio IP addresses (AppleJeus variant 6).