DEEPBREATH is a Swift-based macOS data-mining malware used in UNC1069 intrusions, a financially motivated threat actor assessed to have a DPRK nexus and also tracked as CryptoCore and MASAN. It has been observed in targeted social-engineering campaigns against cryptocurrency and financial-sector victims, including intrusions initiated through fake Zoom meetings, Telegram outreach, and ClickFix-style command execution. DEEPBREATH is deployed as part of a broader macOS toolchain that has included WAVESHAPER, HYPERCALL, HIDDENCALL, SUGARLOADER, SILENCELIFT, and CHROMEPUSH.
Its core capability is bypassing macOS Transparency, Consent, and Control (TCC) protections by manipulating the user-specific TCC database rather than relying on user prompts. Reported behavior includes using Finder’s Full Disk Access to stage and modify TCC.db, injecting permissions to gain broad filesystem access to locations such as Desktop, Documents, and Downloads, restoring the modified database, and relaunching itself via AppleScript with the -autodata argument for background collection. With this access, DEEPBREATH steals data from login.keychain-db, browser cookies and login data from Google Chrome, Brave, and Microsoft Edge, local browser extension settings, Telegram data, and Apple Notes databases. Reporting also states it can steal iCloud Keychain credentials. Stolen data has been described as archived into ZIP files and exfiltrated using curl.
High-confidence associations in the content tie DEEPBREATH to UNC1069 operations targeting the cryptocurrency sector and individual victims for credential theft, browser/session theft, and broader host data collection to support financial theft and follow-on social engineering. Mentioned indicators and artifacts include the use of the -autodata argument and TCC database modification activity on macOS.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Their tooling, including the WAVESHAPER backdoor, HYPERCALL downloader, DEEPBREATH data miner, and CHROMEPUSH browser extension stealer, was designed for deep, persistent compromise of individual machines.
...deploys a Swift-based data miner called DEEPBREATH. DEEPBREATH is equipped to manipulate macOS's Transparency, Consent, and Control (TCC) database... enabling it to steal iCloud Keychain credentials, and data from Google Chrome, Brave, and Microsoft Edge, Telegram, and the Apple Notes application.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Browser Data: Copies cookies, login data, and local extension settings from major browsers including Google Chrome, Brave, and Microsoft Edge across all user profiles
Credentials: Steals login credentials from the user keychain (login.keychain-db)
"Credentials: Steals login credentials from the user keychain (login.keychain-db)"
Messaging and Notes: Exfiltrates user data from two different versions of Telegram and also targets and copies database files from Apple Notes
“steal… Telegram databases, and Apple Notes content.”
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A data-mining malware component used for deep, persistent compromise of individual machines.
Swift-based stealer that bypasses macOS TCC by staging/modifying the TCC database (leveraging Finder Full Disk Access) to access and steal Keychain credentials, browser artifacts (Chrome/Brave/Edge), Telegram databases, and Apple Notes; archives data to ZIP and exfiltrates via curl.
Custom data-mining/stealer component used in a North Korea-linked attack to collect sensitive data (noted broadly as ‘vacuum up everything from browser data to Telegram messages and Apple Notes’) to enable immediate crypto theft and future impersonation.
Swift-based macOS data miner/stealer that manipulates TCC to expand file access and steals credentials and application/browser data (including iCloud Keychain, browsers, Telegram, Apple Notes).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.