WAVESHAPER is a C++ backdoor associated with the DPRK-linked, financially motivated UNC1069 threat cluster, also tracked as CryptoCore and MASAN. It has been used primarily against cryptocurrency, Web3, financial-technology, and venture-capital targets following social-engineering operations involving impersonated contacts, fraudulent video meetings, and ClickFix-style execution lures. The backdoor performs host reconnaissance, communicates with command-and-control infrastructure over HTTP or HTTPS, and supports remote command execution and delivery and execution of additional payloads. WAVESHAPER has been used to deploy follow-on tooling including downloaders, interactive backdoors, and credential- and browser-data-stealing components. WAVESHAPER.V2 is an evolved cross-platform implementation deployed through a compromise of npm software packages; its Windows, macOS, and Linux variants use a shared command protocol, periodically beacon for instructions, collect host and process information, execute scripts or commands, enumerate directories, and execute additional payloads. The supply-chain delivery chain also employed obfuscation and anti-forensic cleanup to conceal its installation trigger. Mandiant and Google Threat Intelligence Group have assessed WAVESHAPER.V2 as an evolution of WAVESHAPER and attributed associated activity to UNC1069.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The macOS Mach-O binary delivered by the plain-crypto-js postinstall hook exhibits significant overlap with WAVESHAPER, a C++ backdoor tracked by Mandiant and attributed to UNC1069.
Based on the above attribution analysis, we assess that the com.apple.act.mond trojan used in the current incident is the WAVESHAPER trojan, and that the threat organization behind it is the Lazarus APT Group.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
With that access, publishing a malicious package to npm requires no additional authentication bypass.
In this attack, Lazarus hijacked an Axios maintainer account to publish malicious versions, covertly planting the malicious dependency plain-crypto-js@4.2.1.
The trojan's main function supports parsing C2 commands and executing the corresponding basic remote control functions: process termination, shell execution, process injection (DoActionIjt), script execution (DoRunScpt / DoActionScpt)...
Linux: Python RAT загружался в /tmp/ld.py и запускался через nohup для persistence (T1059.006 - Python, Execution)
The package.json introduces a postinstall trigger that executes the malicious setup.js file. The setup.js that runs is obfuscated JavaScript code.
This package uses a postinstall hook to automatically execute a script that downloads a remote access trojan, enabling device compromise and data theft.
After the trojan runs with the C2_url, it first collects basic host information including hostname, username, OS type and version, CPU information, system time, and the user process list.
It then beacons to the C2 provided in the parameters — http://sfrclak.com:8000/6202033 — using the hardcoded UA: mozilla/4.0 (compatible; msie 8.0; windows nt 5.1; trident/4.0).
Recommended action: Organizations that installed axios v1.14.1 or v0.30.4 should check for platform-specific IOCs... Block C2 domain sfrclak[.]com and IP 142.11.206[.]73.
The function of this JS file is to detect the platform of the host, use the relevant packages.npm.org/ URL as a parameter to download the payload appropriate for the host system, and execute the download of the subsequent trojan carrying the attacker's C2_url parameter.
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cross-platform trojan/backdoor used in DPRK-linked supply-chain activity. The article uses WAVESHAPER as the attribution anchor for the axios compromise, citing matching drop paths, User-Agent strings, process collection commands, and YARA detections.
Named malware/tool listed in an ESET APT activity report; no further detail is provided in the content.
A backdoor used for deep, persistent compromise of individual machines.
Used in UNC1069 social engineering operations to harvest credentials and enable financial theft; in this case it was deployed via a fake update prompt during a Teams call and stole npm credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.