REF7001 is a Democratic People’s Republic of Korea (DPRK)-attributed intrusion set with assessed technical and infrastructure overlaps with the Lazarus Group. It has targeted blockchain engineers, including personnel associated with cryptocurrency-exchange and wallet-service environments, using social engineering on Discord and similar channels. The group has used cryptocurrency-arbitrage and trading-application lures to induce victims to execute trojanized Python projects on macOS. Its macOS toolchain includes SUGARLOADER, HLOADER, and the KANDYKORN remote-access trojan. SUGARLOADER retrieves payloads and configuration data and reflectively loads KANDYKORN in memory, while HLOADER can masquerade as a legitimate application to maintain persistence. KANDYKORN supports encrypted command-and-control communications, host and process discovery, command execution, interactive shells, file collection and transfer, archive creation, data exfiltration, secure deletion, process termination, and configuration updates. REF7001 activity has also been associated with theft of developer cloud credentials and reconnaissance of cloud environments supporting cryptocurrency services. The observed tradecraft emphasizes in-memory execution, self-deletion, application masquerading, and selective manipulation of trusted cryptocurrency-wallet workflows.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
24 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison for prior social-engineering tradecraft targeting developers.
DPRK-attributed intrusion set targeting blockchain engineers at cryptocurrency-exchange-related organizations. It uses a Discord-delivered Python arbitrage-bot lure to deploy a multistage macOS toolchain culminating in the KANDYKORN in-memory RAT for command execution, discovery, payload transfer, and data exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.