logo

North Korean Hackers Target macOS Users in Cryptocurrency Theft Campaign

ID: 765fe38b-212e-55d1-924e-4aee707a9fdb

STIX ID: report--765fe38b-212e-55d1-924e-4aee707a9fdb

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-06-03

Date Updated: 2026-06-08

...
...

A North Korean-linked APT named Sapphire Sleet is running an active, multi-stage macOS malware campaign targeting cryptocurrency firms, VCs, and Web3 developers by luring victims with a fake Zoom SDK update delivered via Telegram, email, or professional platforms; the malware abuses AppleScript and native macOS components to persist, evade detection, and exfiltrate cryptocurrency wallets, SSH keys, browser extension data and other sensitive information to attacker-controlled servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.