logo

Dissecting Sapphire Sleet’s macOS intrusion from lure to compromise

ID: f62bf742-72a9-5ea4-bd93-8f3cfe5f0497

STIX ID: report--f62bf742-72a9-5ea4-bd93-8f3cfe5f0497

Feed Name: Microsoft Security

Threat Score
90/100

Date Published: 2026-04-16

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence and Microsoft Defender Security Research Team

...
...

Microsoft Threat Intelligence documents a macOS-focused intrusion campaign by the North Korean APT Sapphire Sleet that abuses social engineering (malicious compiled AppleScript lures) and cascading curl→osascript chains to deploy multiple backdoors and a credential harvester; the actor bypasses macOS protections (TCC, Gatekeeper), establishes persistence via launch daemons, performs reflective in-memory loading, and exfiltrates wallets, keychains, browser data, Telegram sessions and other sensitive artifacts, with detailed IOCs, hunting queries, and mitigation guidance provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.