Fake Zoom SDK Update Delivers Sapphire Sleet Malware in New macOS Intrusion Chain
ID: 85f93a0a-25c5-54ec-b8c7-6ba066191dae
STIX ID: report--85f93a0a-25c5-54ec-b8c7-6ba066191dae
Feed Name: cybersecurityNews.com
Microsoft researchers attribute a new macOS-targeting campaign to the North Korean APT group Sapphire Sleet that uses a social-engineered lure (a compiled AppleScript distributed as “Zoom SDK Update.scpt”) to execute multi-stage payloads which harvest passwords, browser and wallet credentials, Telegram session data, SSH keys and keychain items, persist via a misleading LaunchDaemon, manipulate the TCC database to avoid consent prompts, and exfiltrate stolen data to attacker servers; Apple and Microsoft have deployed mitigations to block known components.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
