logo

Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign

ID: 9d8cb598-70c2-5a25-b035-38e1f93c46ad

STIX ID: report--9d8cb598-70c2-5a25-b035-38e1f93c46ad

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
90/100

Date Published: 2026-05-28

Date Updated: 2026-05-28

Author: Maor Gabay

...
...

This report describes a sophisticated macOS intrusion campaign by North Korea–linked Sapphire Sleet that uses targeted social engineering (fake Zoom SDK updates) and native macOS binaries (Script Editor, osascript, Finder) to bypass privacy protections, harvest credentials and cryptographic assets, maintain persistence via LaunchDaemons and reflective in-memory loading, and exfiltrate staged archives to identified C2 infrastructure; the document includes detailed TTPs and IoCs (SHA‑256 hashes, domains, IPs, ports) for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.