CSIDB logo
Threat actor

NEODYMIUM

Attribution profile

Type
Nation State
Location
China
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-08-01 02:30
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

NEODYMIUM is an alias used to track a threat actor whose location is known to be China according to the provided context. The actor is monitored by Elastic Security Labs under the intrusion set designation REF9134, and very little is publicly known about the actor beyond the observed use of custom tools written in Python and Swift that are designed to gather data and execute arbitrary commands on compromised hosts. The actor’s activity has been observed in a specific intrusion set that deployed a macOS backdoor dubbed JokerSpy against a Japanese cryptocurrency exchange.

In the observed intrusion, the actor employed a multi‑stage toolkit that included the JokerSpy backdoor, the Swiftbelt enumeration tool, a self‑signed multi‑architecture binary named xcc, and a Python implant referred to as sh.py. The xcc binary was engineered to check for FullDiskAccess and ScreenRecording permissions on macOS systems and was signed as XProtectCheck in an attempt to masquerade as Apple’s built‑in antivirus technology. To bypass macOS Transparency, Consent, and Control (TCC) protections, the actor attempted to create a replacement TCC database and replace the existing one. The xcc binary was launched via Bash through three commonly used development applications—IntelliJ IDEA, iTerm, and Visual Studio Code—suggesting that backdoored versions of software development tools were likely used as an initial access vector. The sh.py implant functioned as a conduit to deliver additional post‑exploitation tools such as Swiftbelt, which invokes Swift code to avoid generating traditional command‑line artifacts, and variants of xcc were also noted to be written in Swift.

The intrusion specifically targeted a large Japan‑based cryptocurrency service provider that facilitates the trading of Bitcoin, Ethereum and other common cryptocurrencies, although the provider’s name was not disclosed in the reporting. Beyond the observed targeting of a cryptocurrency exchange and the reliance on Python‑ and Swift‑based tools for data gathering and command execution, no further details about the actor’s motives, size, sponsorship, or broader campaign history are provided in the source material. Consequently, the known profile of NEODYMIUM is limited to its alias, its known location in China, its association with the REF9134 intrusion set, and the specific tools and tactics observed in the JokerSpy macOS backdoor operation against a Japanese cryptocurrency exchange.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB