Sapphire Sleet Targets macOS Users In New Social Engineering Campaign, Microsoft Warns
ID: 31796e9d-0298-54ec-9b04-4b0187f40f93
STIX ID: report--31796e9d-0298-54ec-9b04-4b0187f40f93
Feed Name: Cyber Press
Microsoft attributes a macOS social-engineering campaign to North Korea’s Sapphire Sleet, where victims were tricked into running a malicious AppleScript disguised as a Zoom SDK update; the script leveraged Script Editor and TCC database manipulation to bypass Gatekeeper and other protections and exfiltrate cryptocurrency wallets, browser credentials, keychain items, SSH keys, and other sensitive files. Apple added Safari Safe Browsing and XProtect signatures to block the infrastructure, while Microsoft recommended user training, inspection of .scpt files and curl-to-interpreter chains, monitoring for TCC tampering and suspicious LaunchDaemon entries, and protecting browser credential stores and crypto wallets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
