systemupdate.app is a macOS credential-harvesting malware component used in a multi-stage campaign attributed by Microsoft Threat Intelligence to the North Korean threat actor Sapphire Sleet. It is delivered as part of a socially engineered infection chain centered on a fake Zoom SDK update and fraudulent job interview workflows, targeting victims in cryptocurrency, finance, venture capital, and blockchain sectors. The malware masquerades as a legitimate macOS system update utility and displays a native-looking password prompt claiming a software update requires the user’s password. When the victim enters credentials, systemupdate.app validates the password locally against the authentication database and immediately exfiltrates it to the operator via the Telegram Bot API. In the observed chain, mac-cur2 delivers systemupdate.app, mac-cur4 downloads a compressed archive containing it, and a second fake application, softwareupdate.app, displays a false "system update complete" message to reduce suspicion. The broader campaign also included staged AppleScript and curl-to-osascript execution, TCC database manipulation, persistence via LaunchDaemon entries, and theft of Telegram data, browser credentials, cryptocurrency wallet keys, SSH keys, and keychain data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The mac-cur2 stage delivers the credential harvester, “systemupdate.app,” which displays a native password dialog identical to a real system prompt. When the user enters their password, the malware validates it against the local authentication database and immediately sends it to Sapphire Sleet via the Telegram Bot API. A second fake application named “softwareupdate.app” then displays a “system update complete” message so the victim has no reason to grow suspicious.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The script invokes the legitimate macOS “softwareupdate” binary with an invalid parameter to mimic a real system process... A backdoor named “services” simultaneously installs a launch daemon called “com.google.webkit.service.plist,” named to closely mimic legitimate Apple and Google services so it persists across reboots without drawing attention.
The dialog prompts the user to enter their password 'to complete a software update,' and this allows Sapphire Sleet to obtain valid user credentials, exfiltrating them by using the Telegram Bot API.
The mac-cur2 stage delivers the credential harvester, “systemupdate.app,” which displays a native password dialog identical to a real system prompt. When the user enters their password, the malware validates it against the local authentication database and immediately sends it to Sapphire Sleet via the Telegram Bot API.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS credential-harvesting and data-stealing component used in Sapphire Sleet’s fake Zoom SDK update campaign. It presents a fake native password prompt, validates the entered password locally, exfiltrates it via Telegram Bot API, and supports broader theft of browser credentials, crypto wallet keys, SSH keys, Telegram session data, and keychain data.
A fake macOS update application used to harvest the victim's password via a convincing native-looking prompt, validate the password locally, and exfiltrate it through the Telegram Bot API.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.