Fake Zoom SDK Update Spreads Sapphire Sleet Malware in New macOS Attack Chain
ID: a77d77cd-0381-5150-9f34-7dc66431298a
STIX ID: report--a77d77cd-0381-5150-9f34-7dc66431298a
Feed Name: GBHackers
Microsoft uncovered a Sapphire Sleet (North Korean) macOS campaign that uses social engineering—fake recruiter profiles and a compiled AppleScript lured as a “Zoom SDK Update.scpt”—to trick users into running code via Script Editor. The staged chain downloads and executes payloads in memory (osascript/curl), alters the TCC database to bypass consent prompts, installs launch daemons for persistence, harvests credentials and sensitive artifacts (browser data, crypto wallets, SSH keys, Telegram sessions, Apple Notes), and exfiltrates data (including passwords via Telegram API); Apple and Microsoft have deployed detections to block the observed infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
