#WAVESHAPER

Malware/Tool

2026-02-10 • UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering

WAVESHAPER.V2 is a cross-platform remote access trojan and evolution of the WAVESHAPER backdoor, attributed to financially motivated North Korea-nexus actor UNC1069. In the Axios npm supply-chain compromise, malicious Axios releases introduced plain-crypto-js as a runtime dependency; its SILKBELL dropper then retrieved WAVESHAPER.V2. Reported variants use Windows PowerShell, a macOS Mach-O executable, and Linux Python. Across platforms, the malware contacts the same C2 endpoint over port 8000 every 60 seconds, using Base64-encoded JSON and a spoofed Internet Explorer 8 user-agent. Platform-specific POST bodies identify Windows, macOS, or Linux so the server can return the corresponding payload. CrowdStrike tracks the same RAT as ZshBucket.

Tagged Reports

« Back