logo

UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering

ID: 3019ec1e-8798-54ee-bc1f-05c3e64b8241

STIX ID: report--3019ec1e-8798-54ee-bc1f-05c3e64b8241

Feed Name: Threat Intelligence

Threat Score
80/100

Date Published: 2026-02-09

Date Updated: 2026-04-27

Author: Mandiant

...
...

This report describes a macOS intrusion involving DEEPBREATH, a Swift data miner that circumvents macOS TCC by staging and modifying TCC.db to grant broad file and keychain access (using Finder FDA and AppleScript for stealth), SUGARLOADER, a UNC1069-associated downloader that retrieves next-stage payloads from C2s (e.g., breakdream.com, dreamdie.com), and CHROMEPUSH, a C++ native-messaging browser extension that exfiltrates cookies, credentials, and keystrokes from Chromium-based browsers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.