Malware

North Korean Hackers launch new macOS crypto malware

0

North Korean threat actors are launching highly targeted campaigns against cryptocurrency firms using AI-generated videos and the ClickFix technique to deliver malware to macOS and Windows systems.

According to Google Mandiant, the financially motivated operation was linked to the UNC1069 group, which has been tracked since 2018. The attackers targeted a fintech company and deployed an unusually large toolkit of malware families to maximize data theft and enable future social engineering.

Attack chain
The campaign relied heavily on social engineering. The victim was contacted via Telegram from a compromised executive account at a crypto company. After building trust, the attackers shared a Calendly link that led to a fake Zoom meeting page hosted on attacker infrastructure.

During the fake meeting, the victim was shown a deepfake video of a cryptocurrency CEO. The attackers then staged audio issues and instructed the victim to run troubleshooting commands from a webpage, triggering the malware infection on both macOS and Windows systems.

Similar tactics were observed in 2025 by Huntress, which linked related campaigns to the North Korean BlueNoroff group.

macOS malware toolkit
Mandiant identified AppleScript activity followed by a Mach-O payload and seven macOS malware families:

  • WAVESHAPER: C++ backdoor collecting system data and downloading additional payloads.
  • HYPERCALL: Golang downloader using RC4-encrypted configs and WebSocket C2 communication.
  • HIDDENCALL: Backdoor injected by HYPERCALL for remote command execution and file access.
  • SILENCELIFT: Minimal backdoor that reports system info and can disrupt Telegram with root access.
  • DEEPBREATH: Swift-based data stealer that bypasses macOS TCC to steal credentials and sensitive data.
  • SUGARLOADER: Downloader with persistent launch daemon configuration.
  • CHROMEPUSH: Browser stealer disguised as a Google Docs Offline extension, capturing credentials and screenshots.

Mandiant noted that SILENCELIFT, DEEPBREATH, and CHROMEPUSH are newly observed tools for UNC1069. The volume of malware deployed against a single victim was described as highly unusual.

The campaign aims to steal cryptocurrency and gather identity data for future social engineering attacks. UNC1069 has continuously evolved its tooling and targeting strategy, shifting from general Web3 targets to financial services, payments, brokerages, and wallet infrastructure in recent years.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

OpenClaw adds VirusTotal Scanning to block malicious skills

Previous article

Dutch Govt hit by Ivanti EPMM breach

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *