Initial research exposing JOKERSPY
ID: ccc6c023-0832-5551-bb33-4c25638fe6ce
STIX ID: report--ccc6c023-0832-5551-bb33-4c25638fe6ce
Feed Name: Elastic Security Labs
Threat Score
Elastic Security Labs details REF9134, an active intrusion targeting a major Japanese cryptocurrency exchange that leverages a self-signed macOS Swift binary (xcc/JokerSpy) to probe and bypass TCC permissions, deploys the Python backdoor sh.py to beacon to C2 and execute payloads, and runs the Swiftbelt enumeration tool; the report includes timeline, TTPs, IOCs (domains and SHA-256 hashes), and YARA detection rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
