North Korean actors blend ClickFix with new macOS backdoors in Crypto campaign

by

North Korean actors blend ClickFix with new macOS backdoors in Crypto campaign

WAVESHAPER functioned as the primary backdoor, establishing remote access and enabling additional payload delivery. HYPERCALL operated as a downloader, retrieving secondary components such as HIDDENCALL, which provided further command execution capabilities. This staged deployment allowed the threat actor to expand control over the compromised macOS system in phases rather than dropping a single large payload.

DEEPBREATH, a Swift-based infostealer, focused on harvesting sensitive data from the host. According to the researchers, it manipulated Apple’s Transparency, Consent, and Control (TCC) framework to access protected resources without prompting the user. That enabled the collection of browser data, keychain material, and messaging content. CHROMEPUSH, meanwhile, targeted browser environments, including session cookies and authentication tokens.

The researchers also observed abuse of macOS security mechanisms, including functionalities on Apple’s XProtect system. Instead of disabling protections right away, the malware leveraged trusted system components and expected behaviors to reduce detection visibility.