AppleJack
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known by the alias AppleJack (also observed as AppleJ4ck) is an Israeli‑based individual who operated as a principal owner and mastermind of the vDOS distributed denial‑of‑service‑for‑hire service. Multiple references in vDOS support tickets and associated phone numbers place the actor in Israel, including statements from support staff who identified themselves as being from the country. The vDOS service generated more than six hundred thousand dollars in revenue over a two‑year period by selling DDoS attack capacity to customers. Payments were accepted via Bitcoin, PayPal and, for a brief period, credit cards, with the service offering subscription tiers based on attack duration.
The actor’s core activity was providing a booter platform that allowed users to launch distributed denial‑of‑service attacks against targets of their choosing. To avoid attracting attention from Israeli authorities, the service’s support staff blacklisted all Israeli IP ranges, as evidenced by ticket responses in which employees stated they were from Israel and did not want to affect local sites. The actor’s infrastructure relied on Cloudflare to conceal the true origin IP address (82.118.233.144) while the actual attack servers were hosted on rented systems in Bulgaria through Verdina.net. Administrative alerts were sent via an SMS gateway (Nexmo) to six mobile numbers, two of which are registered to Israeli individuals Itay Huri and Yarden Bidani. Email correspondence was handled through Mailgun, with the associated keys exposed in the leaked vDOS database. Bitcoin payments were processed through an intermediary server at 45.55.55.193 (a Digital Ocean host in the United States) before reaching the Bulgarian servers, and PayPal proceeds were laundered through a round‑robin chain of accounts described in the actor’s own recruitment posts on Hackforums. The actor marketed the service on Hackforums under the aliases AppleJack, AppleJ4ck, P1st (also known as P1st0) and M30w.
The vDOS platform was responsible for more than 150,000 DDoS attacks and generated over 277 million seconds of attack time between April and July 2016, which the reporting source characterized as roughly 8.81 years of attack traffic. In September 2016, after the vDOS operators were exposed and arrested, the actor claimed responsibility for a sustained DDoS attack exceeding 140 Gbps against the KrebsOnSecurity website, with attack packets containing the taunt “godiefaggot.” The actor’s support tickets demonstrate a deliberate policy of not attacking Israeli IP ranges, indicating a desire to avoid local legal scrutiny. Although the service advertised capabilities up to 50 Gbps, independent testing observed attack volumes of 14 Gbps and 6 Gbps, which were still sufficient to overwhelm unprotected sites. The actor also accepted Bitcoin payments via Coinbase, using an intermediary server to obscure the flow of funds.
Attribution to the actor is derived from the leaked vDOS database, support ticket conversations, and associated phone numbers and email addresses that trace back to individuals in Israel. The source material does not explicitly state any state sponsorship or affiliation with a larger criminal consortium, describing the operation as an independent criminal enterprise run by two Israeli hackers. The actor’s aliases appear in Hackforums posts where they recruited others to assist with PayPal laundering and discussed the service’s day‑to‑day operation. Overall, the actor’s activities are characterized as financially motivated DDoS‑for‑hire operations conducted from Israel with infrastructure distributed across Bulgaria and the United States.
Incidents
Attributed incidents are available to members.
1 incident