HYPERCALL is a Golang/Go-based downloader and backdoor component used by the DPRK-nexus threat actor UNC1069, also tracked as CryptoCore and MASAN, in financially motivated intrusions targeting the cryptocurrency and broader Web3 sector. It has been observed in social-engineering-driven compromise chains in which victims are lured through fake Zoom or meeting workflows, including ClickFix-style troubleshooting prompts, leading to malware execution on macOS. Mandiant reporting describes HYPERCALL as one of the initial malicious files deployed alongside WAVESHAPER, where it is used to expand the attacker’s foothold and serve additional payloads.
Its documented behavior includes reading an RC4-encrypted configuration, connecting to command-and-control infrastructure over WebSockets on TCP 443, downloading malicious dynamic libraries from C2, and reflectively loading those libraries into memory. In observed UNC1069 operations, HYPERCALL was used to deliver additional malware including HIDDENCALL, a Golang backdoor providing interactive access, and DEEPBREATH, a Swift-based data theft component. The broader intrusion set associated with HYPERCALL also included WAVESHAPER, SUGARLOADER, SILENCELIFT, and CHROMEPUSH.
The malware has been linked to intrusions against cryptocurrency-sector organizations and individuals, including a FinTech victim, as part of campaigns aimed at credential theft, browser/session theft, and ultimately cryptocurrency theft and follow-on social engineering. High-confidence associated behaviors from the surrounding intrusion include theft of Keychain credentials, browser artifacts from Chrome, Brave, and Edge, Telegram data, Apple Notes data, cookies, and keystrokes by companion tooling. No standalone IOC set for HYPERCALL beyond its RC4-encrypted configuration handling, WebSocket C2 over TCP 443, and reflective DLL loading is provided in the source content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Their tooling, including the WAVESHAPER backdoor, HYPERCALL downloader, DEEPBREATH data miner, and CHROMEPUSH browser extension stealer, was designed for deep, persistent compromise of individual machines.
...distribute a Go-based downloader codenamed HYPERCALL, which is then used to serve additional payloads...
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The fake meeting infrastructure is built to look genuine. Attackers use real SDKs and CSS from platforms like Zoom and Microsoft Teams to recreate the interface. The call appears in-browser, with no application to install, until the audio 'fails.'
When Wessman refused to run the app, the attackers made a last-ditch attempt to get him to run a curl command in his terminal, then went dark and deleted all conversations.
At that point, the victim is prompted to fix the issue, either by clicking a link that downloads a malicious AppleScript or by running a command pasted into the terminal.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A downloader used as part of tooling for deep, persistent compromise of individual machines.
Go-based downloader that decrypts configuration with RC4 and reflectively loads dynamic libraries from C2; used to deliver additional payloads (HIDDENCALL, SUGARLOADER, SILENCELIFT).
Custom backdoor deployed alongside other tooling in a North Korea-linked operation against a crypto executive, supporting persistent access and follow-on collection/theft.
Go-based downloader used to fetch and deliver follow-on payloads to compromised macOS systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.