logo

North Korean Hackers Target macOS Users in Cryptocurrency Theft Campaign

ID: d944865a-9c78-561a-b84e-fc9bb3a3fb2b

STIX ID: report--d944865a-9c78-561a-b84e-fc9bb3a3fb2b

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-06-03

Date Updated: 2026-06-21

...
...

A North Korean APT known as Sapphire Sleet is conducting a high-severity macOS malware campaign targeting cryptocurrency firms, venture capital and Web3 developers by luring victims to install a fake Zoom SDK update (delivered via Telegram, email, and professional platforms); the multi-stage AppleScript-based malware harvests cryptocurrency wallets, SSH keys, browser extension and Telegram session data and exfiltrates it to North Korean-controlled C2 servers, with recommended defenses including user education, AppleScript and Finder activity monitoring, hardened macOS configurations, and MFA enforcement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.