logo

North Korean APT Targets macOS to Steal Crypto Wallets and SSH Keys

ID: c958332f-f6e5-5f96-90e2-2ce945ab20d1

STIX ID: report--c958332f-f6e5-5f96-90e2-2ce945ab20d1

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: Mayura Kathir

...
...

This report details a macOS intrusion campaign attributed to the North Korean APT 'Sapphire Sleet' (BlueNoroff/UNC1069) targeting venture capital, Web3 developers, and cryptocurrency platforms since at least 2020; attackers use social engineering (fake Zoom SDK), malicious AppleScript, abuse of macOS privacy controls (TCC/Finder), persistence via launch daemons, in-memory payload loading, and encrypted exfiltration to steal wallets, credentials, and other sensitive data, and the report includes multiple file paths and SHA-256 IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.