logo

Initial research exposing JOKERSPY

ID: ccc6c023-0832-5551-bb33-4c25638fe6ce

STIX ID: report--ccc6c023-0832-5551-bb33-4c25638fe6ce

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2023-06-21

Date Updated: 2026-04-27

...
...

Elastic Security Labs details REF9134, an active intrusion targeting a major Japanese cryptocurrency exchange that leverages a self-signed macOS Swift binary (xcc/JokerSpy) to probe and bypass TCC permissions, deploys the Python backdoor sh.py to beacon to C2 and execute payloads, and runs the Swiftbelt enumeration tool; the report includes timeline, TTPs, IOCs (domains and SHA-256 hashes), and YARA detection rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.