SUGARLOADER is a C++ downloader and loader used in North Korea-linked intrusion activity targeting cryptocurrency, Web3, and related financial-sector victims, particularly on macOS. It has been associated with UNC1069 and has also appeared in operations overlapping with tooling linked to Lazarus/BlueNoroff tradecraft. The malware is designed to retrieve and execute next-stage payloads, often using RC4-encrypted configuration data and resilient command-and-control logic with primary and fallback infrastructure. On macOS, SUGARLOADER has been observed as an obfuscated Mach-O binary employing anti-analysis techniques such as packed code, junk instructions, opaque predicates, indirect control flow, and memory checksum validation.
A notable use of SUGARLOADER appeared in multi-stage macOS compromises delivered through social engineering. In one intrusion chain targeting blockchain engineers, victims were lured through Discord into running malicious Python components that downloaded SUGARLOADER, which then fetched and reflectively loaded additional payloads in memory. In that campaign, SUGARLOADER was used to deploy later-stage components including HLOADER and ultimately the KANDYKORN backdoor, while supporting persistence through a companion component that hijacked the execution flow of the legitimate Discord application. SUGARLOADER has also been observed in financially motivated UNC1069 intrusions initiated through fake Zoom or Teams meeting scenarios and ClickFix-style execution lures, where it was used to deploy CHROMEPUSH, a Chromium-focused data-stealing component.
The malware supports in-memory execution of downloaded Mach-O payloads rather than relying solely on disk writes, reducing forensic visibility and aiding defense evasion. It can obtain configuration either from command-line parameters or from an encrypted local configuration file, depending on the variant. Observed variants on macOS used RC4-encrypted communications and custom handshake logic for command-and-control. Persistence has been established in some intrusions through manually created launch daemons masquerading as benign system components. SUGARLOADER’s operational role is primarily as a staging mechanism for follow-on malware that enables credential theft, browser and session data theft, reconnaissance, and broader post-compromise activity against high-value cryptocurrency and Web3 targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SUGARLOADER is a downloader written in C++ historically associated with UNC1069 intrusions. Based on the observations from this intrusion, SUGARLOADER was solely used to deploy CHROMEPUSH.
SysPhon ... and SUGARLOADER, a known loader previously utilized to deliver the KANDYKORN malware.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
By leveraging social media platforms like Discord with enticing lures, these actors are finding new paths into highly targeted environments.
SUGARLOADER uses this to retrieve and execute the KANDYKORN remote access trojan in-memory via NSCreateObjectFileImageFromMemory and NSLinkModule.
Numerous junk instructions, opaque predicates and indirect jumps in memory are present within the packed code, complicating the analysis of the unpacking process.
The victim believed they were installing an arbitrage bot, a software tool designed to profit from cryptocurrency rate differences between platforms.
When the malware first connects to the C2 server during the initialization phase, a handshake must be validated to proceed.
Operating covertly, KANDYKORN employs a feature-rich multi-staged loader paired with a custom network protocol to facilitate a range of post-compromise activities.
The decrypted SUGARLOADER configuration for the sample analysed by Mandiant included the following C&C servers: breakdream[.]com:443 dreamdie[.]com:443
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family used in UNC1069 operations supporting credential harvesting and financial theft.
Known C++ downloader used in the intrusion chain; configured with an RC4-encrypted file, persisted via a launch daemon masquerading as a system updater, and used to deploy CHROMEPUSH.
Malware family observed in an intrusion chain associated with AI-enabled social engineering; part of a toolset enabling credential/browser data theft, keystroke logging, and C2 communications (campaign also referenced RC4-encrypted configurations).
C++ downloader/loader used to deploy additional payloads, including CHROMEPUSH.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.