macOS Users Targeted by Sapphire Sleet Campaign Using Script Editor and Fake Update Dialogs
ID: a2baeaf8-00cc-5eac-ba5e-d420ad802271
STIX ID: report--a2baeaf8-00cc-5eac-ba5e-d420ad802271
Feed Name: Cyber Press
A North Korean-linked cyberespionage campaign called "Sapphire Sleet" targets macOS users in cryptocurrency, venture capital, and blockchain sectors using deceptive AppleScript lure files that hide malicious code beneath benign comments; the chain fetches staged payloads into memory, deploys fake system update dialogs to capture passwords, manipulates permissions to access browser wallets, SSH keys and notes, and exfiltrates data while maintaining stealth. The report includes staged execution and persistence TTPs and two SHA-256 indicators of compromise for the lure files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
