The North Korean advanced persistent threat (APT) group known as Sapphire Sleet has launched a highly sophisticated malware campaign targeting macOS environments.
Active since 2020, the threat actor is now focusing on high-value financial targets, including Web3 developers, venture capital firms, and cryptocurrency organizations.
Rather than using traditional technical exploits, this new campaign relies heavily on trust abuse. The attackers manipulate native macOS applications to silently steal cryptocurrency wallets, SSH keys, and critical corporate data.
North Korean Mac Malware
The intrusion begins with targeted social engineering. Attackers pose as recruiters or investors on professional platforms like LinkedIn and Telegram to schedule video meetings with victims.
Before the meeting, the attacker instructs the target to install a fake Zoom component named Zoom SDK Update.scpt.
When the victim executes this file, it opens natively in the macOS Script Editor. The attackers hide the malicious logic using thousands of empty lines of whitespace to keep it out of immediate view.
Once running, the script initiates a sequence of commands using hardcoded User Agents to establish a connection to the attacker’s server and drop initial profiling tools.

To steal credentials, the malware launches a fake system update application that displays a native-looking password prompt. However, the most technical aspect of the attack is its privacy bypass.
The malware abuses the native macOS Finder application, which holds Full Disk Access by default, to overwrite the system’s privacy database.
This silent modification grants full automation permissions to the system’s scripting tools, completely bypassing macOS security alerts.
According to levelblue research, the attackers install a disguised startup process that loads a backdoor directly into memory at system boot.
The malware then actively hunts for specific files, including cryptocurrency wallets like Exodus and Ledger Live, Telegram session profiles, local SSH keys, and Apple Notes. These archived files are then secretly uploaded to remote attacker infrastructure.
Core Indicators of Compromise
While Apple and Microsoft have mitigated some of the original campaign infrastructure, security teams should actively monitor for the following indicators of compromise (IoCs).
The attackers can quickly pivot to new domains and payloads, but their core behaviors remain detectable.
| Type | Indicator / Value | Context / Component Path |
|---|---|---|
| SHA-256 | 2075fd1a1362d188290910a8c55cf30c11ed5955c04af410c481410f538da419 | /Users/<user>/Downloads/Zoom SDK Update.scpt |
| SHA-256 | 05e1761b535537287e7b72d103a29c4453742725600f59a34a4831eafc0b8e53 | /Users/<user>/com.apple.cli |
| SHA-256 | 5fbbca2d72840feb86b6ef8a1abb4fe2f225d84228a714391673be2719c73ac7 | /Users/<user>/Library/Services/services / icloudz |
| SHA-256 | 5e581f22f56883ee13358f73fabab00fcf9313a053210eb12ac18e66098346e5 | com.google.chromes.updaters |
| SHA-256 | 95e893e7cdde19d7d16ff5a5074d0b369abd31c1a30962656133caa8153e8d63 | com.google.webkit.service.plist |
| SHA-256 | 8fd5b8db10458ace7e4ed335eb0c66527e1928ad87a3c688595804f72b205e8c | /private/tmp/SystemUpdate/systemupdate.app/Contents/MacOS/Mac Password Popup |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.