North Korean Hackers Deploy New macOS Malware for Cryptocurrency Theft
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
North Korean hackers have been identified using advanced techniques to target the cryptocurrency sector, specifically through tailored campaigns that leverage AI-generated videos and social engineering. This attack was attributed to the UNC1069 group, which has been active since 2018. During a recent investigation by Google’s Mandiant researchers, they discovered that the attackers used a compromised Telegram account of an executive from a cryptocurrency company to initiate contact with potential victims.
The hackers built rapport with their targets and shared a Calendly link that directed them to a spoofed Zoom meeting page. In this meeting, they presented a deepfake video of a CEO from another cryptocurrency firm, creating a deceptive environment that led to the execution of malicious commands on the victim’s device.
Mandiant’s research revealed seven distinct macOS malware families deployed during the attack, showcasing the complexity and sophistication of the threat. The malware included WAVESHAPER, a C++ backdoor, and DEEPBREATH, a Swift-based data miner that bypasses macOS protections to steal sensitive information.
The identified malware families are:
- WAVESHAPER – C++ backdoor that runs as a background daemon, collects host system information, communicates with C2 over HTTP/HTTPS using curl, and downloads and executes follow-on payloads.
- HYPERCALL – Golang-based downloader that reads an RC4-encrypted configuration file, connects to C2 over WebSockets on TCP 443, downloads malicious dynamic libraries, and reflectively loads them into memory.
- HIDDENCALL – Golang-based backdoor reflectively injected by HYPERCALL that provides hands-on keyboard access, supports command execution and file operations, and deploys additional malware.
- SILENCELIFT – Minimal C/C++ backdoor that beacons host information and lock screen status to a hard-coded C2 server and can interrupt Telegram communications when executed with root privileges.
- DEEPBREATH – Swift-based data miner deployed via HIDDENCALL that bypasses macOS TCC protections by modifying the TCC database to gain broad filesystem access and steals keychain credentials, browser data, Telegram data, and Apple Notes data.
- SUGARLOADER – C++ downloader that uses an RC4-encrypted configuration to retrieve next-stage payloads and was made persistent via a manually created launch daemon.
- CHROMEPUSH – C++ browser data miner deployed by SUGARLOADER that installs as a Chromium native messaging host masquerading as a Google Docs Offline extension and collects keystrokes, credentials, cookies, and optionally screenshots.
This incident highlights the increasing sophistication of cyber threats targeting the cryptocurrency industry, particularly through social engineering and advanced malware techniques. The volume of malware deployed against a single individual indicates a targeted approach aimed at maximizing data collection for future theft and social engineering efforts.
Since 2018, UNC1069 has shown an ability to adapt and evolve its tactics, shifting its focus to the Web3 industry in 2023. This evolution underscores the need for heightened vigilance among cryptocurrency firms and users regarding potential phishing attempts and malware infections.
Key Takeaways
- Be cautious of unsolicited communications, especially those involving links to meetings or downloads.
- Verify the identity of individuals before engaging in discussions about sensitive topics like cryptocurrency.
- Implement strong security measures, such as multi-factor authentication, on all accounts related to cryptocurrency.
- Regularly update software and security tools to protect against the latest malware threats.
- Educate employees about social engineering tactics and the risks associated with deepfake technology.
Key Terms & Concepts
- UNC1069: In this article, UNC1069 refers to a North Korean threat group known for targeting the cryptocurrency sector since 2018.
- deepfake: In this article, a deepfake refers to AI-generated video content that impersonates real individuals, often used in social engineering attacks.
- macOS: In this article, macOS refers to the operating system used by Apple computers, which is targeted by specific malware families.
- malware: In this article, malware refers to malicious software designed to disrupt, damage, or gain unauthorized access to computer systems.
- social engineering: In this article, social engineering refers to tactics used by attackers to manipulate individuals into divulging confidential information.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.