SUGARLOADER

First seen
2019-08-01 00:00:00
Malware type
loader
Profile updated
2026-07-07 14:36:51

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications

Context

SUGARLOADER is a malware loader designed to deliver various types of malicious payloads to compromised systems. It typically serves as an intermediary in multi-stage attacks, often targeting industries such as financial services and healthcare.

Reports & references

  • sentinelone.com — Dprk Crypto Theft Macos Rustbucket Droppers Pivot To Deliver Kandykorn Payloads (report)
  • elastic.co — Elastic Catches Dprk Passing Out Kandykorn (report)
  • virusbulletin.com — Sugarcoating Kandykorn A Sweet Dive Into A Sophisticated Macos Backdoor (report)
  • malpedia.caad.fkie.fraunhofer.de — Osx.Sugarloader (report)
  • cloud.google.com — Unc1069 Targets Cryptocurrency Ai Social Engineering (report)

External references