logo

Microsoft spots Sapphire Sleet macOS attack using AppleScript and social engineering

ID: a60415b7-0dfa-52ea-850f-c55df0621984

STIX ID: report--a60415b7-0dfa-52ea-850f-c55df0621984

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-04-21

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A macOS-focused campaign attributed to the North Korean APT Sapphire Sleet uses social-engineering lures (fake recruiter messages and a "Zoom SDK Update.scpt" AppleScript) to execute multi-stage payloads that bypass macOS protections, establish persistence, harvest credentials and cryptocurrency-related data, and exfiltrate information to attacker-controlled servers; Microsoft and Apple have deployed detections and advised defensive measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.