G1049 · ATT&CK 19.1 group
AppleJeus
[AppleJeus](https://attack.mitre.org/groups/G1049) is a North Korean state-sponsored threat group attributed to the Reconnaissance General Bureau. Associated with the broader [Lazarus Group](https://attack.mitre.org/groups/G0032) umbrella of actors, [AppleJeus](https://attack.mitre.org/groups/G1049) has been active since at least 2018 and is closely aligned in resources with TEMP.hermit, another DPRK-affiliated group under the same umbrella.(Citation: dtex DPRK 2025 structure ITworkers) The group’s primary mission is to generate and launder revenue to provide financial support to the government. [AppleJeus](https://attack.mitre.org/groups/G1049) primarily targets the cryptocurrency industry and is most notably responsible for the [3CX Supply Chain Attack](https://attack.mitre.org/campaigns/C0057).(Citation: Mandiant 3cx UNC4736 2023) The group traditionally deploys malicious cryptocurrency software in combination with [Phishing](https://attack.mitre.org/techniques/T1566). From these compromised environments, it selectively deploys additional backdoors to enable extended operations against high-value financial targets.(Citation: Mandiant DPRK Groups 2023)(Citation: JPCert Blog Laz Subgroups 2025)
Aliases: AppleJeus, Citrine Sleet, Gleaming Pisces, UNC1720, UNC4736
Mapped techniques (2)
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Cyber Threat Intelligence (CTI) · explicit-nameModule 12 — Human-layer and physical testing
Red Team & Offensive Security · explicit-nameMalware, phishing, ransomware, and behavior extraction
Digital Forensics & Incident Response (DFIR) · explicit-nameHuman, workload, pipeline, and emergency identity
Cloud Security · explicit-nameScenario-based cyber risk assessment and treatment
Governance, Risk & Compliance (GRC) · explicit-nameGovernance, organizational context, and accountable authority
Governance, Risk & Compliance (GRC) · topic-matchModule 4 — Web applications and APIs
Red Team & Offensive Security · tactic-routeModule 3 — Telemetry and logging architecture
Blue Team & Defensive Security · tactic-routeThreat modeling and secure architecture
Secure Code & Application Security · tactic-routeLinux and macOS endpoint forensics
Digital Forensics & Incident Response (DFIR) · tactic-routePolicy architecture, standards, procedures, and exceptions
Governance, Risk & Compliance (GRC) · tactic-routeModule 6 — Alert triage, investigation, and escalation
Blue Team & Defensive Security · tactic-route