SUGARLOADER is a C++ downloader/loader used in macOS intrusion chains and historically associated with UNC1069, a financially motivated North Korea-linked threat actor targeting cryptocurrency, Web3, and related financial-sector organizations. It has also been referenced in activity linked to BlueNoroff/SnatchCrypto reporting and in prior macOS campaigns involving KANDYKORN. Reported delivery chains include social-engineering-led infections where FinderTools downloaded and executed SUGARLOADER at /Users/Shared/.sld, and later UNC1069 intrusions where it was deployed alongside malware such as WAVESHAPER, HYPERCALL, DEEPBREATH, SILENCELIFT, and CHROMEPUSH.
Its core role is next-stage payload retrieval and deployment. In KANDYKORN-related reporting, FinderTools passed a hardcoded C2 address to SUGARLOADER, which checked for configuration at /Library/Caches/com.apple.safari.ck, retrieved a C2 URL from that file, and in one observed intrusion used 23.254.226.90 over TCP port 44. It then downloaded HLOADER to /Applications/Discord.app/Contents/MacOS/Discord; HLOADER renamed the legitimate Discord binary to .lock and restored it during execution to maintain persistence. SUGARLOADER also copied into the Discord application hierarchy as .log and appname under /Applications/Discord.app/Contents/MacOS/. In that campaign, SUGARLOADER loaded the KANDYKORN RAT in memory using NSCreateObjectFileImageFromMemory and NSLinkModule.
In later UNC1069 activity, SUGARLOADER was described as using an RC4-encrypted configuration with a hard-coded 32-byte key. If run without command-line arguments, it checked for /Library/OSRecovery/com.apple.os.config; after decryption, the configuration could contain up to two URLs for retrieving the next-stage payload, querying the first and only falling back if needed. Mandiant reported analyzed SUGARLOADER samples containing C2 servers breakdream[.]com:443 and dreamdie[.]com:443. In the observed intrusion, SUGARLOADER was used solely to deploy CHROMEPUSH and was made persistent via a manually created launch daemon masquerading as a system updater.
Associated capabilities and outcomes attributed to chains using SUGARLOADER include deployment of browser-focused stealers, credential theft, keystroke logging, cookie theft, and broader financial-theft enablement. CHROMEPUSH, one payload delivered by SUGARLOADER, was described as a C++ Chromium-extension-based stealer targeting Chrome and Brave, collecting keystrokes, credentials, and cookies, and persisting via a native messaging host path such as %HOME%/Library/Application Support/Google/Chrome/NativeMessagingHosts/Google Chrome Docs/ with manifest com.google.docs.offline.json.
High-confidence indicators and artifacts mentioned in the content include /Users/Shared/.sld, /Library/Caches/com.apple.safari.ck, /Library/OSRecovery/com.apple.os.config, /Applications/Discord.app/Contents/MacOS/Discord, /Applications/Discord.app/Contents/MacOS/.log, /Applications/Discord.app/Contents/MacOS/appname, 23.254.226.90:44, breakdream[.]com:443, and dreamdie[.]com:443.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SUGARLOADER is a downloader written in C++ historically associated with UNC1069 intrusions. Based on the observations from this intrusion, SUGARLOADER was solely used to deploy CHROMEPUSH.
SysPhon ... and SUGARLOADER, a known loader previously utilized to deliver the KANDYKORN malware.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
“…detailing… AI-augmented phishing…” and “UNC1069 intrusion… through AI-enabled social engineering and a fake Zoom ClickFix lure.”
SUGARLOADER uses this to retrieve and execute the KANDYKORN remote access trojan in-memory via NSCreateObjectFileImageFromMemory and NSLinkModule.
“after RC4 decryption of configuration data… SUGARLOADER, configured with an RC4-encrypted file…”
The main executable uses curl to reach out to docs-send.online/getBalance/usdt/ethereum... communicating over TCP port 44.
The decrypted SUGARLOADER configuration for the sample analysed by Mandiant included the following C&C servers: breakdream[.]com:443 dreamdie[.]com:443
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family used in UNC1069 operations supporting credential harvesting and financial theft.
Known C++ downloader used in the intrusion chain; configured with an RC4-encrypted file, persisted via a launch daemon masquerading as a system updater, and used to deploy CHROMEPUSH.
Malware family observed in an intrusion chain associated with AI-enabled social engineering; part of a toolset enabling credential/browser data theft, keystroke logging, and C2 communications (campaign also referenced RC4-encrypted configurations).
C++ downloader/loader used to deploy additional payloads, including CHROMEPUSH.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.