logo

North Korean hackers use new macOS malware in crypto-theft attacks

ID: 6357e995-894e-5c61-8b8a-cb20b1837896

STIX ID: report--6357e995-894e-5c61-8b8a-cb20b1837896

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-02-10

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Executive summary:** Mandiant attributes a targeted UNC1069 campaign against the cryptocurrency sector that leveraged Telegram/Calendly deepfake Zoom meetings and social engineering to install macOS and Windows malware; investigators identified seven macOS families (WAVESHAPER, HYPERCALL, HIDDENCALL, SILENCELIFT, DEEPBREATH, SUGARLOADER, CHROMEPUSH) used for backdoors, downloaders, and extensive data theft (keychain, browser, Telegram, Notes) to enable crypto theft and future social-engineering operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.