Fake Zoom SDK Update Delivers Sapphire Sleet Malware On macOS

Microsoft Threat Intelligence has exposed a sophisticated macOS campaign orchestrated by Sapphire Sleet, a North Korean state-sponsored threat actor, using a deceptive Zoom SDK update to steal credentials, cryptocurrency assets, and sensitive personal data from targeted users.

Rather than exploiting software vulnerabilities, the campaign relies entirely on social engineering manipulating victims into manually running malicious files that silently bypass macOS’s built-in security protections.

How The Attack Unfolds

Sapphire Sleet active since at least March 2020 and primarily focused on cryptocurrency, venture capital, and blockchain organizations follows a well-documented social engineering playbook.

The threat actor creates fake recruiter profiles on LinkedIn and other professional networking platforms, engages targets with fabricated job opportunities, schedules mock technical interviews, and then instructs victims to install what appears to be a legitimate video conferencing tool or software developer kit (SDK) update.

Initial access: The .scpt lure file as seen in macOS Script Editor (Source: microsoft)
Initial access: The .scpt lure file as seen in macOS Script Editor (Source: microsoft)

In this campaign, victims were directed to download a file named Zoom SDK Update.scpt a compiled AppleScript that opens by default in macOS Script Editor, a trusted first-party Apple application capable of executing arbitrary shell commands.

The malicious script is crafted to mimic a genuine Zoom SDK update, displaying a large decoy comment block of benign-looking upgrade instructions at the top.

Beyond credential theft, the campaign deploys multiple backdoors to maintain long-term access.

A primary backdoor named services is installed alongside a host monitoring component called com.apple.cli, which beacons to the threat actor’s command-and-control (C2) server at 83.136.208[.]246:6783.

The AppleScript lure with decoy content and payload execution (Source: microsoft)
The AppleScript lure with decoy content and payload execution (Source: microsoft)

Additional backdoors iCloud and com. google. chrome. updaters are deployed using naming conventions designed to impersonate legitimate Apple and Google files.

A launch daemon configuration file ensures automatic execution at every system reboot, even when no user is logged in.

Process tree showing cascading execution from Script Editor (Source: microsoft)
Process tree showing cascading execution from Script Editor (Source: microsoft)

The final exfiltration stage runs a 575-line AppleScript payload that systematically collects and uploads seven categories of sensitive data: Telegram session files, browser credentials and cookies, macOS keychains, cryptocurrency desktop wallet data (Ledger Live, Exodus), SSH keys and shell history, Apple Notes databases, and system logs.

Cryptocurrency wallet extension data stored in browser IndexedDB is selectively targeted, reflecting a highly deliberate, financially motivated operation.

Microsoft has shared its findings with Apple as part of responsible disclosure.

Apple has since deployed XProtect signatures and Apple Safe Browsing protections in Safari to detect and block malware and infrastructure linked to this campaign and macOS devices receive these updates automatically.

Organizations and individuals in the cryptocurrency, digital assets, and finance sectors are advised to remain especially vigilant against unsolicited recruiter outreach, verify the source of any software update requests, and ensure all macOS devices are running the latest security updates.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories