SysPhon is a C++ downloader associated with the North Korea-linked BlueNoroff threat actor, a Lazarus Group sub-cluster, and observed in the broader SnatchCrypto activity, including the GhostCall/GhostHire reporting. It is described as a lightweight RustBucket-related variant and has also been linked with SUGARLOADER. Its documented functionality is to perform host reconnaissance, post collected system information to command-and-control infrastructure, and retrieve a binary payload from an external server. Reporting states it functions similarly to the third component of RustBucket, which was originally developed in Rust and later rewritten in Swift, and that SysPhon likely leads to deployment of KANDYKORN or another backdoor. The malware has been discussed in the context of campaigns targeting blockchain/Web3 organizations, including developers, executives, and managers, with a strong macOS focus in GhostCall-related intrusion chains. High-confidence behavior directly mentioned in the content is limited to reconnaissance and payload retrieval; no specific indicators of compromise for SysPhon itself were provided in the supplied content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SysPhon is a downloader written in C++ that functions similarly to the third component of the RustBucket malware, which was initially developed in Rust and later rewritten in Swift.
SysPhon ... is a downloader written in C++ that can conduct reconnaissance and fetch a binary payload from an external server.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
RooTroy collects and lists all mounted volumes and running processes... SneakMain.macOS constructs a JSON object containing this information, along with additional fields such as... process list... SysPhon... Process list ps aux.
all three DownTroy strains collect comprehensive system information including OS details, domain name, host name, username, proxy settings, and VM detection alongside process lists... SysPhon... conduct system reconnaissance by executing a series of commands.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a named malware/tool via hashtag only; no behavioral details are provided in the content.
C++ downloader (described as a lightweight RustBucket variant) used for reconnaissance and fetching a binary payload from an external server; noted as used in the Hidden Risk campaign and alongside SUGARLOADER.
A C++ downloader used in a chain with older BlueNoroff tooling. It performs host reconnaissance, posts system data to C2, and executes or exits based on server response. It was observed alongside SugarLoader and likely used to fetch later-stage payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.