SILENCELIFT is a minimal C/C++ backdoor/beacon identified by Mandiant in an intrusion attributed to UNC1069, a financially motivated threat actor assessed with high confidence to have a North Korea nexus and also tracked as CryptoCore and MASAN. It was observed in a targeted campaign against a cryptocurrency-sector FinTech organization. The intrusion used social engineering via a compromised Telegram account, a Calendly link, and a spoofed Zoom meeting page, where the victim was tricked into executing ClickFix-style troubleshooting commands on macOS. In the resulting multi-stage infection chain, SILENCELIFT was deployed alongside other malware families including WAVESHAPER, HYPERCALL, HIDDENCALL, SUGARLOADER, DEEPBREATH, and CHROMEPUSH. SILENCELIFT is described as a minimalist backdoor that beacons host information, including lock screen status, to a hard-coded command-and-control server. One reported C2 was support-zoom[.]us. When executed with root privileges, it can interrupt Telegram communications. The malware was part of a broader toolset used to harvest host and victim data in operations targeting the cryptocurrency and Web3 sector for financial theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...deployment of seven unique malware families, including a new set of tooling designed to capture host and victim data: SILENCELIFT, DEEPBREATH and CHROMEPUSH.
...several new malware families, such as SILENCELIFT... A minimalist C/C++ backdoor referred to as SILENCELIFT, which sends system information to a command-and-control (C2) server.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Minimal C/C++ beacon used for host reconnaissance/telemetry collection (host details).
Minimalist C/C++ backdoor that beacons system information to a C2 server.
Minimalistic macOS backdoor that beacons host information to C2 and can disrupt Telegram communications when running with root privileges.
Newly named tooling reported by Google Mandiant as part of an intrusion set; described as capturing host and victim data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.