logo

Fake Zoom SDK Update Delivers Sapphire Sleet Malware in New macOS Intrusion Chain

ID: 85f93a0a-25c5-54ec-b8c7-6ba066191dae

STIX ID: report--85f93a0a-25c5-54ec-b8c7-6ba066191dae

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-04-17

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Microsoft researchers attribute a new macOS-targeting campaign to the North Korean APT group Sapphire Sleet that uses a social-engineered lure (a compiled AppleScript distributed as “Zoom SDK Update.scpt”) to execute multi-stage payloads which harvest passwords, browser and wallet credentials, Telegram session data, SSH keys and keychain items, persist via a misleading LaunchDaemon, manipulate the TCC database to avoid consent prompts, and exfiltrate stolen data to attacker servers; Apple and Microsoft have deployed mitigations to block known components.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.