Fake Zoom SDK Update Delivers Sapphire Sleet Malware On macOS
ID: 18a426fd-c433-5a9c-ac35-f3383c23dc7b
STIX ID: report--18a426fd-c433-5a9c-ac35-f3383c23dc7b
Feed Name: Cyber Press
Microsoft Threat Intelligence details a Sapphire Sleet macOS campaign leveraging social-engineered AppleScript “Zoom SDK Update” lures to bypass macOS protections, install backdoors (services, iCloud, com.google.chrome.updaters, com.apple.cli) that beacon to a C2 at 83.136.208.246:6783, and run a large AppleScript payload that exfiltrates Telegram sessions, browser credentials/cookies/IndexedDB wallet data, macOS keychains, cryptocurrency wallet files, SSH keys, Apple Notes, and system logs; Microsoft disclosed findings to Apple, which deployed XProtect and Safe Browsing protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
