logo

Fake Zoom SDK Update Spreads Sapphire Sleet Malware in New macOS Attack Chain

ID: a77d77cd-0381-5150-9f34-7dc66431298a

STIX ID: report--a77d77cd-0381-5150-9f34-7dc66431298a

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-04-17

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Microsoft uncovered a Sapphire Sleet (North Korean) macOS campaign that uses social engineering—fake recruiter profiles and a compiled AppleScript lured as a “Zoom SDK Update.scpt”—to trick users into running code via Script Editor. The staged chain downloads and executes payloads in memory (osascript/curl), alters the TCC database to bypass consent prompts, installs launch daemons for persistence, harvests credentials and sensitive artifacts (browser data, crypto wallets, SSH keys, Telegram sessions, Apple Notes), and exfiltrates data (including passwords via Telegram API); Apple and Microsoft have deployed detections to block the observed infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.