HIDDENCALL is a Golang-based backdoor used in UNC1069 (aka CryptoCore/MASAN; assessed DPRK-linked) intrusions targeting cryptocurrency/Web3 and related fintech organizations for financially motivated theft. In the described attack chain, victims were socially engineered via Telegram impersonation/compromised accounts, a Calendly link redirecting to a spoofed Zoom domain, and a fake Zoom meeting that prompted ClickFix-style “troubleshooting” command execution. On macOS, this led to AppleScript activity and deployment of WAVESHAPER (packed C++ backdoor), which facilitated delivery of HYPERCALL (Go downloader). HYPERCALL then delivered and reflectively injected HIDDENCALL into memory.
Per the provided reporting, HIDDENCALL provides interactive “hands-on keyboard” access to the compromised system, supports command execution and file operations, and can deploy additional malware. It was used to deploy follow-on components such as DEEPBREATH (Swift-based data theft component) in the observed operation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"HIDDENCALL – Golang-based backdoor reflectively injected by HYPERCALL that provides hands-on keyboard access, supports command execution and file operations, and deploys additional malware."
A follow-on Golang backdoor component known as HIDDENCALL, which provides hands-on keyboard access to the compromised system...
4 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Golang backdoor providing interactive access on the victim host.
Go-based backdoor providing interactive (hands-on-keyboard) access to compromised macOS hosts and enabling deployment of additional tooling.
Golang backdoor injected by HYPERCALL providing interactive access, command execution, file operations, and additional malware deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.