North Korean hackers use new macOS malware in crypto-theft attacks
ID: 6357e995-894e-5c61-8b8a-cb20b1837896
STIX ID: report--6357e995-894e-5c61-8b8a-cb20b1837896
Feed Name: Bleeping Computer
**Executive summary:** Mandiant attributes a targeted UNC1069 campaign against the cryptocurrency sector that leveraged Telegram/Calendly deepfake Zoom meetings and social engineering to install macOS and Windows malware; investigators identified seven macOS families (WAVESHAPER, HYPERCALL, HIDDENCALL, SILENCELIFT, DEEPBREATH, SUGARLOADER, CHROMEPUSH) used for backdoors, downloaders, and extensive data theft (keychain, browser, Telegram, Notes) to enable crypto theft and future social-engineering operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
