North Korean Hackers Target macOS Users in Cryptocurrency Theft Campaign
ID: d944865a-9c78-561a-b84e-fc9bb3a3fb2b
STIX ID: report--d944865a-9c78-561a-b84e-fc9bb3a3fb2b
Feed Name: ThreatCluster
A North Korean APT known as Sapphire Sleet is conducting a high-severity macOS malware campaign targeting cryptocurrency firms, venture capital and Web3 developers by luring victims to install a fake Zoom SDK update (delivered via Telegram, email, and professional platforms); the multi-stage AppleScript-based malware harvests cryptocurrency wallets, SSH keys, browser extension and Telegram session data and exfiltrates it to North Korean-controlled C2 servers, with recommended defenses including user education, AppleScript and Finder activity monitoring, hardened macOS configurations, and MFA enforcement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
