logo

North Korea targets macOS users in latest heist

ID: 02b221da-5805-5c9e-88c1-606c9100451d

STIX ID: report--02b221da-5805-5c9e-88c1-606c9100451d

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-04-16

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Sapphire Sleet, an offshoot of the Lazarus Group, is running a targeted social‑engineering campaign against finance professionals that lures victims with fake recruiter messages and a malicious macOS "Zoom SDK Update.scpt" AppleScript. The script hides malicious logic beneath decoy content and uses staged curl commands to load additional AppleScript payloads that deploy backdoors (e.g., icloudz), a credential stealer that drops systemupdate.app, and other tools to bypass macOS protections and exfiltrate wallets, credentials and sensitive files via Telegram and C2 infrastructure; Microsoft disclosed the campaign and Apple deployed platform mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.