SUGARLOADER is a C++ macOS downloader associated with financially motivated UNC1069 activity and also observed in DPRK-linked intrusions with overlaps to Lazarus Group tradecraft. It uses an RC4-encrypted configuration to obtain command-and-control settings, supports primary and fallback servers, retrieves next-stage Mach-O payloads, and can execute them directly from memory through reflective loading. SUGARLOADER has delivered KANDYKORN in cryptocurrency-sector targeting and CHROMEPUSH in intrusions against cryptocurrency and financial-technology organizations. It has been deployed in multi-stage, socially engineered infections involving fake meeting lures and ClickFix-style user execution. Observed persistence mechanisms include a manually created macOS launch daemon and use alongside a Discord-application hijacking component. SUGARLOADER employs packing, control-flow obfuscation, and in-memory unpacking to hinder analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SUGARLOADER connects to C2, creates or decrypts its RC4-encrypted configuration, downloads KANDYKORN, and executes it directly in memory using reflective binary loading.
SUGARLOADER is a downloader written in C++ historically associated with UNC1069 intrusions. Based on the observations from this intrusion, SUGARLOADER was solely used to deploy CHROMEPUSH.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
By leveraging social media platforms like Discord with enticing lures, these actors are finding new paths into highly targeted environments.
SUGARLOADER uses this to retrieve and execute the KANDYKORN remote access trojan in-memory via NSCreateObjectFileImageFromMemory and NSLinkModule.
Numerous junk instructions, opaque predicates and indirect jumps in memory are present within the packed code, complicating the analysis of the unpacking process.
SUGARLOADER... is obfuscated using a binary packer... code used to unpack the binary in memory.
The victim believed they were installing an arbitrage bot, a software tool designed to profit from cryptocurrency rate differences between platforms.
When the breakpoint is hit, the code will already be decrypted in memory... The configuration file is encrypted using RC4... read into memory and decrypted.
When the malware first connects to the C2 server during the initialization phase, a handshake must be validated to proceed.
FinderTools... download[s] and execut[es] a hidden second stage payload .sld... The second instance... renamed to .log.
It supports two C2 servers, one as the main server, and the second one as a fallback.
Operating covertly, KANDYKORN employs a feature-rich multi-staged loader paired with a custom network protocol to facilitate a range of post-compromise activities.
The decrypted SUGARLOADER configuration for the sample analysed by Mandiant included the following C&C servers: breakdream[.]com:443 dreamdie[.]com:443
Watcher.py... fetches content from [a] Google Drive URL... written into the testSpeed.py file. testSpeed.py... fetches another Python file... FinderTools... downloading and executing... .sld.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family used in UNC1069 operations supporting credential harvesting and financial theft.
Known C++ downloader used in the intrusion chain; configured with an RC4-encrypted file, persisted via a launch daemon masquerading as a system updater, and used to deploy CHROMEPUSH.
Malware family observed in an intrusion chain associated with AI-enabled social engineering; part of a toolset enabling credential/browser data theft, keystroke logging, and C2 communications (campaign also referenced RC4-encrypted configurations).
C++ downloader/loader used to deploy additional payloads, including CHROMEPUSH.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.