TF-MAL-osx.sugarloader
📛 Threat Title
Malware family: SUGARLOADER
Description
ThreatFox malware family `osx.sugarloader`. Printable name: SUGARLOADER.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.sugarloader
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.sugarloader
IOC database
- Type
- domain
- Value
osx.sugarloader- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.sugarloader
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.sugarloader
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
SocGholish is a JavaScript-based loader malware that has been used since at least 2017. It has been observed in use against multiple sectors globally for initial access, primarily through drive-by-downloads masquerading as software updates.
-
web:cloud.google.com
Subsequently, Mandiant identified seven distinct malware families during the forensic analysis of the compromised system, with SUGARLOADER being the only malware family already tracked by Mandiant prior to the investigation.
-
web:coinspaidmedia.com
Lazarus Group hackers are using a new type of malware called Kandykorn. It enters the victim's computer through social engineering techniques and a special loader program called Sugarloader .
-
web:hivepro.com
The UNC1069 cryptocurrency attack resulted in the deployment of seven distinct malware families — WAVESHAPER, SUGARLOADER , SILENCELIFT, HYPERCALL, DEEPBREATH, HIDDENCALL, and CHROMEPUSH — engineered to harvest credentials, browser data, messaging content, and session tokens to facilitate large-scale cryptocurrency theft.
-
web:labs.cloudsecurityalliance.org
Axios Poisoned: UNC1069's npm Supply Chain Playbook Key Takeaways On March 31, 2026, the npm package axios — the most downloaded JavaScript HTTP client library with over 100 million weekly downloads — was compromised after a North Korea-nexus threat actor designated UNC1069 socially engineered the project's lead maintainer [1] [2]. The attack introduced a malicious transitive ...
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the SUGARLOADER malware family including references, samples and yara signatures.
-
web:www.breachsense.com
Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.ncsc.gov.uk
How to defend organisations against malware or ransomware attacks.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.