services is a macOS backdoor used by the North Korean threat actor Sapphire Sleet in a socially engineered campaign that used a fake Zoom SDK update during fraudulent job interview workflows. In the reported infection chain, services functioned as the primary backdoor and persistence installer. It was deployed during the mac-cur1 stage alongside a host monitoring component named com.apple.cli. The malware established persistence by installing a LaunchDaemon plist named com.google.webkit.service.plist under /Library/LaunchDaemons, using naming intended to resemble legitimate Apple or Google services. Reported artifacts associated with services include an installation marker at ~/Library/Application Support/Authorization/auth.db and error logging to /tmp/lg4err. Microsoft also reported an icloudz backdoor as a renamed copy of services that used NSCreateObjectFileImageFromMemory to load payloads directly into memory. The broader Sapphire Sleet campaign targeted macOS users in cryptocurrency, finance, venture capital, and blockchain sectors and relied on user-executed AppleScript rather than software exploitation. Associated activity in the same campaign included credential harvesting via systemupdate.app, TCC database manipulation, and exfiltration of Telegram session data, browser credentials, cryptocurrency wallet data, SSH keys, keychain data, Apple Notes, shell history, and system logs.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A backdoor named “services” simultaneously installs a launch daemon called “com.google.webkit.service.plist,” named to closely mimic legitimate Apple and Google services so it persists across reboots without drawing attention.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
The script invokes the legitimate macOS “softwareupdate” binary with an invalid parameter to mimic a real system process... A backdoor named “services” simultaneously installs a launch daemon called “com.google.webkit.service.plist,” named to closely mimic legitimate Apple and Google services so it persists across reboots without drawing attention.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A persistence-focused macOS backdoor used in the campaign to maintain access across reboots by installing a deceptive LaunchDaemon plist masquerading as a legitimate service.
Primary macOS backdoor and persistence installer. It provides interactive command execution, installs persistence via a launch daemon, and deploys additional backdoors including icloudz and com.google.chromes.updaters.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.