Skip to main content
Mallory
MalwareUsed by 2 actors

icloudz

icloudz is a macOS backdoor used in a social-engineering campaign attributed by Microsoft to the North Korean threat actor Sapphire Sleet, also known as APT38 and described in the reporting as linked to Lazarus. The campaign targeted macOS users, particularly in finance-, cryptocurrency-, venture capital-, and blockchain-related contexts, using fake recruiter personas and counterfeit Zoom interview/support lures to convince victims to open a malicious AppleScript file named "Zoom SDK Update.scpt." Within this intrusion chain, icloudz was deployed as a backdoor named to mimic a legitimate iCloud-related artifact. Its key documented capability is loading additional payloads directly into memory via the macOS NSCreateObjectFileImageFromMemory API, enabling further in-memory delivery and execution of attacker-controlled code. Reporting also states that icloudz was a renamed copy of the previously deployed "services" backdoor and shared the same SHA-256 hash, indicating identical underlying code. In the broader campaign, associated malware and payload stages performed orchestration, persistence, reconnaissance, TCC bypass, credential theft, and exfiltration of sensitive data including credentials, cryptocurrency wallet data, browser data, keychains, Apple Notes, Telegram data, SSH keys, and system information. High-confidence related artifacts and behaviors mentioned alongside icloudz include the lure file "Zoom SDK Update.scpt," abuse of legitimate macOS utilities such as softwareupdate, curl, and osascript, and Apple-like naming conventions used to disguise malicious components.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
APT38

Aside from deploying a credential stealer that exfiltrates data via Telegram Bot API, the campaign also involved the icloudz backdoor that enabled further in-memory delivery of additional payloads.

via scworldscworld.com
Lazarus

Additionally, one of the backdoors used in this campaign - icloudz - is named to mimic a legitimate iCloud‑related artifact, and also uses the macOS NSCreateObjectFileImageFromMemory API to load additional payloads directly into memory.

via register securitygo.theregister.com
MITRE ATT&CK

Techniques & procedures

6 distinct techniques documented for this family, organized by ATT&CK tactic.

Persistence

1 technique
T1543.004Launch DaemonEvidence1

To ensure continued execution across reboots, a launch daemon configuration file named com.google.webkit.service.plist is installed under /Library/LaunchDaemons . This configuration causes icloudz to launch automatically at system startup, even if no user is signed in.

T1543.004Launch DaemonEvidence1

To ensure continued execution across reboots, a launch daemon configuration file named com.google.webkit.service.plist is installed under /Library/LaunchDaemons . This configuration causes icloudz to launch automatically at system startup, even if no user is signed in.

Stealth

2 techniques
T1036MasqueradingEvidence2
TacticStealth

It's a compiled AppleScript that opens in macOS Script Editor by default and looks like a legitimate Zoom SDK update... Each stage of the campaign also abuses native Apple tools or mimics Apple naming conventions to disguise the illicit activity.

T1620Reflective Code LoadingEvidence2
TacticStealth

Additionally, one of the backdoors used in this campaign - icloudz - is named to mimic a legitimate iCloud-related artifact, and also uses the macOS NSCreateObjectFileImageFromMemory API to load additional payloads directly into memory.

T1071Application Layer ProtocolEvidence1

Each curl user agent fetches a different piece of malware that serves its own purpose in the attack chain, from orchestration and backdooring victims' machines, to reconnaissance and registering the compromised system with Sapphire Sleet's command-and-control (C2) infrastructure.

T1071.001Web ProtocolsEvidence1

During execution, com.apple.cli performs host reconnaissance while maintaining repeated outbound connectivity to the threat actor-controlled C2 endpoint 83.136.208[.]246:6783.

T1105Ingress Tool TransferEvidence2

the script proceeds to use curl to run a malicious payload retrieving another attacker-controlled script

INDICATORS OF COMPROMISE

IOCs tracked for this family

1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Hashes
1 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in app1 month ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching1

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping6

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.