logo

Hackers Use Fake Software Update Prompts to Steal Passwords and Crypto Wallet Data From macOS Users

ID: 8af95a7a-c6b0-57fc-8d2f-ebbda7f335e6

STIX ID: report--8af95a7a-c6b0-57fc-8d2f-ebbda7f335e6

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Tushar Subhra Dutta

...
...

Microsoft attributes a 2026 social-engineering campaign to North Korean group Sapphire Sleet that targets macOS users in the cryptocurrency, venture capital, and blockchain sectors by luring victims to run malicious AppleScript 'update' files; these deploy fake system update dialogs to harvest passwords, install multiple persistent backdoors (including an in-memory loader), collect wallet files, browser-stored credentials, SSH keys and other sensitive data, and exfiltrate archives to attacker servers while sending credentials via Telegram. The report includes comprehensive IoCs (IPs, domains, filenames, filepaths, tokens, and user-agents) and mitigation recommendations such as blocking downloaded AppleScript files, monitoring macOS TCC changes, and using hardware wallets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.