Sapphire Sleet macOS Malware Abuses curl-to-osascript Execution for Multi-Stage Payload Delivery
ID: be15481f-afab-5c61-940e-f1717d758d38
STIX ID: report--be15481f-afab-5c61-940e-f1717d758d38
Feed Name: GBHackers
Microsoft attributes a macOS espionage campaign to the North Korean actor 'Sapphire Sleet' that uses crafted .scpt AppleScript lures which pipe curl output directly to osascript to run cascading, in-memory stages. The chain deploys monitoring/backdoor services, a credential-harvesting app exfiltrating via Telegram, and programmatic TCC database manipulation to steal high‑value artifacts (keychains, crypto wallets, SSH keys, Telegram sessions). Microsoft and Apple released detections and mitigations; the report includes file hashes and guidance for defenders to monitor piped curl→osascript activity, suspicious osascript behavior, and TCC.db operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
