Beyond Gatekeeper: How Sapphire Sleet’s AppleScript Trap Hijacks macOS and Crypto Wallets
ID: ef6a7d5c-2d71-540c-afca-79324f8ae2a7
STIX ID: report--ef6a7d5c-2d71-540c-afca-79324f8ae2a7
Feed Name: securityonline.info
Microsoft Threat Intelligence attributes a sophisticated, macOS-targeted social engineering campaign to the North Korean APT Sapphire Sleet that leverages fake recruiter profiles and a compiled AppleScript named "Zoom SDK Update.scpt" to coax targets into executing payloads. The multi-stage attack uses cascading curl-fetched AppleScript payloads, establishes persistence via a launch daemon, manipulates the TCC database to inject permissions, and deploys components that harvest cryptocurrency wallets, messaging sessions, keychains, SSH keys, shell history, and Notes for exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
