Microsoft Threat Intelligence has exposed a sophisticated macOS campaign orchestrated by Sapphire Sleet, a North Korean state-sponsored threat actor, using a deceptive Zoom SDK update to steal credentials, cryptocurrency assets, and sensitive personal data from targeted users.
Rather than exploiting software vulnerabilities, the campaign relies entirely on social engineering manipulating victims into manually running malicious files that silently bypass macOS’s built-in security protections.
How The Attack Unfolds
Sapphire Sleet active since at least March 2020 and primarily focused on cryptocurrency, venture capital, and blockchain organizations follows a well-documented social engineering playbook.
The threat actor creates fake recruiter profiles on LinkedIn and other professional networking platforms, engages targets with fabricated job opportunities, schedules mock technical interviews, and then instructs victims to install what appears to be a legitimate video conferencing tool or software developer kit (SDK) update.

In this campaign, victims were directed to download a file named Zoom SDK Update.scpt a compiled AppleScript that opens by default in macOS Script Editor, a trusted first-party Apple application capable of executing arbitrary shell commands.
The malicious script is crafted to mimic a genuine Zoom SDK update, displaying a large decoy comment block of benign-looking upgrade instructions at the top.
Beyond credential theft, the campaign deploys multiple backdoors to maintain long-term access.
A primary backdoor named services is installed alongside a host monitoring component called com.apple.cli, which beacons to the threat actor’s command-and-control (C2) server at 83.136.208[.]246:6783.

Additional backdoors iCloud and com. google. chrome. updaters are deployed using naming conventions designed to impersonate legitimate Apple and Google files.
A launch daemon configuration file ensures automatic execution at every system reboot, even when no user is logged in.

The final exfiltration stage runs a 575-line AppleScript payload that systematically collects and uploads seven categories of sensitive data: Telegram session files, browser credentials and cookies, macOS keychains, cryptocurrency desktop wallet data (Ledger Live, Exodus), SSH keys and shell history, Apple Notes databases, and system logs.
Cryptocurrency wallet extension data stored in browser IndexedDB is selectively targeted, reflecting a highly deliberate, financially motivated operation.
Microsoft has shared its findings with Apple as part of responsible disclosure.
Apple has since deployed XProtect signatures and Apple Safe Browsing protections in Safari to detect and block malware and infrastructure linked to this campaign and macOS devices receive these updates automatically.
Organizations and individuals in the cryptocurrency, digital assets, and finance sectors are advised to remain especially vigilant against unsolicited recruiter outreach, verify the source of any software update requests, and ensure all macOS devices are running the latest security updates.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.