logo

North Korea Uses ClickFix to Target macOS Users' Data

ID: a163b9c4-ca51-5dbe-86d0-39f35ac69b27

STIX ID: report--a163b9c4-ca51-5dbe-86d0-39f35ac69b27

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2026-04-16

Date Updated: 2026-04-22

Author: Alexander Culafi

...
...

Microsoft describes an active macOS-focused ClickFix campaign attributed to North Korean APT 'Sapphire Sleet' that lures targets with fake recruiter interviews and a malicious "Zoom SDK Update.scpt" AppleScript. The attacker chain executes multiple AppleScript payloads to orchestrate beaconing, harvest credentials, steal cryptocurrency wallets and browser data, install persistent backdoors, bypass Apple's TCC security controls, and exfiltrate sensitive data; Microsoft provided mitigations and IoCs and reported the activity to Apple.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.