Microsoft said the North Korea-linked threat group Sapphire Sleet—also tracked as APT38 and tied to the Lazarus ecosystem—targeted macOS users in cryptocurrency, finance, venture capital, and blockchain through social engineering rather than software exploits. The operation reportedly used fake recruiter personas on platforms including LinkedIn to lure victims into sham job interviews, then directed them to open a malicious AppleScript file masquerading as a Zoom update, Zoom SDK Update.scpt. That file launched a multi-stage infection chain using native macOS tools, downloaded additional payloads, and executed in a user-initiated context to help evade protections such as Gatekeeper, notarization, quarantine enforcement, and TCC controls.
The intrusion deployed multiple backdoors, including systemupdate.app, which displayed a fake macOS password prompt to capture credentials, and icloudz, which loaded payloads directly into memory via NSCreateObjectFileImageFromMemory. Microsoft said the malware manipulated the TCC database, established persistence, and exfiltrated cryptocurrency wallets, browser data, Telegram sessions, SSH keys, Apple Notes, keychain material, and other sensitive information, with some stolen credentials sent through the Telegram Bot API. Apple was notified through responsible disclosure and subsequently added Safari Safe Browsing protections and XProtect signatures to detect and block the campaign’s infrastructure and malware.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
After Microsoft notified Apple through responsible disclosure, Apple deployed Safari Safe Browsing protections and XProtect signatures to detect and block the campaign's malware and infrastructure. This response was described as already in place by the time of Microsoft's publication.
Microsoft Threat Intelligence published technical analysis of the macOS intrusion chain, including the fake Zoom update lure, multi-stage payload delivery, persistence mechanisms, credential theft, and theft of wallets, browser data, Telegram sessions, SSH keys, and Apple Notes. The report also provided indicators of compromise, malicious hashes, command-and-control infrastructure, and Defender detection and hunting guidance.
The North Korea-linked threat actor Sapphire Sleet began targeting high-value victims in cryptocurrency, finance, venture capital, and blockchain through fake recruiter outreach and sham job interviews. Victims were tricked into opening a malicious AppleScript file posing as a Zoom SDK update, leading to credential theft, backdoor deployment, and data exfiltration on macOS systems.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 24 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourceinfosec.pub
Open sourceinfosec.pub
Open sourcebsky.app
Open sourcego.theregister.com
Open sourcedarkreading.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.