Find notable cyber news and cases, enriched with sources, timelines, and signals.

UNC1069 seven-family macOS malware deployment

Malware Activity
First reported
Last updated
Happening score
H score 30
3 unique sources, 3 articles

Summary

Hide ▲

UNC1069 first targeted a cryptocurrency-sector fintech with a Telegram-to-Calendly-to-spoofed Zoom ClickFix chain that used AI-generated video, AppleScript, and a malicious Mach-O binary to deploy seven macOS families: WAVESHAPER, HYPERCALL, HIDDENCALL, SILENCILIFT, DEEPBREATH, SUGARLOADER, and CHROMEPUSH. The payloads enabled backdoor access and theft of credentials, browser data, Telegram data, and Apple Notes data, and Mandiant said the goal was cryptocurrency theft plus future identity-based social engineering. Google later attributed the Axios npm supply-chain compromise to the same suspected North Korean cluster and linked WAVESHAPER.V2 to WAVESHAPER, extending the activity to Windows, macOS, and Linux.

Related Happenings

MacOS.Gaslight prompt-injection technique aimed at AI-assisted triage

Technical Analysis
H score23 First: 24.06.2026 17:00 Last: 24.06.2026 17:00 Sources 1

About this happening: macOS.Gaslight is a Rust-based macOS implant and information stealer assessed with high confidence as the work of North Korea-aligned threat actors. The sample uses ...

UNK_DeadDrop developer phishing campaign using fake job and code-review lures

Campaign
H score30 First: 08.06.2026 18:00 Last: 08.06.2026 18:00 Sources 1

About this happening: A UNK_DeadDrop phishing campaign sent more than 250 emails to software developers at almost 100 organizations, using fake job and code-review lures to steal cryptocu...

JINX-0164 cryptocurrency recruitment-lure campaign

Campaign
H score39 First: 28.05.2026 10:54 Last: 28.05.2026 10:54 Sources 1

About this happening: A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...

Mini Shai-Hulud npm supply-chain malware wave

Malware Activity
H score68 First: 12.05.2026 14:07 Last: 12.05.2026 14:07 Sources 1

About this happening: The Mini Shai-Hulud npm malware activity now includes the Miasma variant affecting Microsoft GitHub repositories in a self-replicating supply-chain campaign. O...

Latest development: 09.06.2026 18:42

On June 5, Microsoft removed 73 repositories across its Azure, microsoft, Azure-Samples, and MicrosoftDocs organizations on GitHub after concerns about potential malicious content tied to the Miasma/Shai-Hulud supply-chain campaign. The action disrupted continuous integration pipelines and broke workflows that depended on Azure/functions-action, while Microsoft said it temporarily removed some repositories during its investigation.

Lightning PyPI router_runtime.js credential-stealing payload

Malware Activity
H score29 First: 30.04.2026 19:31 Last: 30.04.2026 19:31 Sources 1

About this happening: The Lightning PyPI package was pushed in malicious versions 2.6.2 and 2.6.3 on April 30, 2026, turning a normal install into credential theft for developer and C...

Latest development: 04.05.2026 20:15

Microsoft Threat Intelligence says Defender detected and prevented the malicious `lightning==2.6.3` routine in customer environments, notified the Lightning maintainer, and warned that users who ran `import lightning` may need to rotate exposed secrets, keys, and tokens.

Timeline

  1. 11.02.2026 00:17 3 articles · 5mo ago

    UNC1069 crypto-sector malware campaign disclosed

    Initial Disclosure

    North Korean hackers linked to UNC1069 targeted a cryptocurrency-sector fintech organization with an AI-generated video and ClickFix social-engineering chain that began on Telegram, moved to a Calendly link and spoofed Zoom meeting page, and led to AppleScript execution, a malicious Mach-O binary, and seven macOS families — WAVESHAPER, HYPERCALL, HIDDENCALL, SILENCELIFT, DEEPBREATH, SUGARLOADER, and CHROMEPUSH — for backdoor access, credential theft, browser data theft, Telegram data theft, Apple Notes theft, and persistent follow-on payload delivery on macOS and Windows.

    Show sources