logo

Sapphire Sleet macOS Malware Abuses curl-to-osascript Execution for Multi-Stage Payload Delivery

ID: be15481f-afab-5c61-940e-f1717d758d38

STIX ID: report--be15481f-afab-5c61-940e-f1717d758d38

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Mayura Kathir

...
...

Microsoft attributes a macOS espionage campaign to the North Korean actor 'Sapphire Sleet' that uses crafted .scpt AppleScript lures which pipe curl output directly to osascript to run cascading, in-memory stages. The chain deploys monitoring/backdoor services, a credential-harvesting app exfiltrating via Telegram, and programmatic TCC database manipulation to steal high‑value artifacts (keychains, crypto wallets, SSH keys, Telegram sessions). Microsoft and Apple released detections and mitigations; the report includes file hashes and guidance for defenders to monitor piped curl→osascript activity, suspicious osascript behavior, and TCC.db operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.