A sophisticated cyberespionage campaign is aggressively targeting Apple computer users across high-value financial sectors worldwide.
North Korean threat actors are leveraging convincing social engineering tactics to bypass built-in platform defenses entirely.
Instead of exploiting traditional software vulnerabilities, this operation tricks victims into executing malicious scripts masked as everyday communication tools.
The targeted attacks specifically focus on cryptocurrency organizations, venture capital firms, and blockchain technology developers, aiming to drain digital wallets and steal operational identities.
This marks a significant escalation in the group’s capabilities and demonstrates their commitment to compromising environments previously considered highly secure.
Sapphire Sleet Targets macOS
The attack sequence begins when a victim opens a compiled AppleScript file, which is launched automatically in the native macOS Script Editor.
The visible portion of the file displays a benign comment block with routine upgrade instructions to establish trust with the user.

To conceal the actual payload, the malicious code is pushed far below the visible window, separated by thousands of blank lines. This clever obfuscation ensures the victim only sees what appears to be a legitimate software notification.
Once triggered, the script launches a harmless command using the system update binary to reinforce the illusion of a standard installation.
Behind the scenes, a cascading execution chain uses network commands to fetch progressively complex payloads directly into system memory.
This staging process drops several hidden components disguised with legitimate vendor naming conventions to avoid raising suspicion.
In the latest campaign variant, payloads are named to mimic Microsoft and Apple helper utilities, ensuring they blend seamlessly into the user profile and evade simple antivirus scans.
The malware also registers the compromised device with external servers by collecting basic system information, such as hardware models and current system time.

This careful staging allows the attackers to maintain stealthy persistence across system reboots.
Microsoft said, the malware deploys a fake system update application that generates a native macOS password dialog. This deceptive prompt is visually identical to authentic system requests for administrative privileges.
When the user enters their password, the malware instantly validates it against the local authentication database to ensure accuracy.
The verified credentials are immediately exfiltrated to the attacker’s infrastructure via automated messaging application programming interfaces.
A secondary application then displays a fake completion screen to ensure the victim remains completely unaware of the compromise.
To steal sensitive files, attackers must first circumvent platform protections that require user consent for data access.
The malware achieves this by directing the native file manager to temporarily rename the system permissions folder, allowing the script to inject unauthorized access rules into the underlying database.
With unrestricted access granted, the operation systematically collects browser profiles, digital wallet keys, secure shell keys, and private application notes.
All stolen data is quietly compressed and uploaded in the background using hidden processes. This completes a highly reliable infection cycle that leaves minimal forensic traces for investigators.
Indicators of Compromise
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.