North Korea targets macOS users in latest heist
ID: 02b221da-5805-5c9e-88c1-606c9100451d
STIX ID: report--02b221da-5805-5c9e-88c1-606c9100451d
Feed Name: The Register (Security)
Sapphire Sleet, an offshoot of the Lazarus Group, is running a targeted social‑engineering campaign against finance professionals that lures victims with fake recruiter messages and a malicious macOS "Zoom SDK Update.scpt" AppleScript. The script hides malicious logic beneath decoy content and uses staged curl commands to load additional AppleScript payloads that deploy backdoors (e.g., icloudz), a credential stealer that drops systemupdate.app, and other tools to bypass macOS protections and exfiltrate wallets, credentials and sensitive files via Telegram and C2 infrastructure; Microsoft disclosed the campaign and Apple deployed platform mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
