Sapphire Sleet is turning the user, not the kernel, into the entry point. The group is using fake update and meeting lures to get macOS users to manually run malware, which bypasses built-in security checks and leaves credentials exposed even when the platform itself is not exploited.
Microsoft says the campaign targets Macs through decoy Zoom updates and other social engineering tied to fake recruiter outreach. The payload steals passwords, cryptocurrency assets, and sensitive data, and Microsoft says Apple has already pushed updates to detect and block the campaign’s infrastructure and malware.
The forward risk is simple. Any workflow that trains users to trust update prompts or support-style instructions can be turned into a delivery path for credential theft, especially in finance and technology environments where account access and crypto holdings are high-value targets.
9 sources · May 6
Community Assessment
Threat researchers add parallel context: ongoing macOS infostealer operations already used fake Homebrew and Claude lure chains, with credential and wallet theft extending the same user-execution risk beyond Zoom decoys.
Supply-chain attacks take aim at your AI coding agents
A North Korean APT has crafted malicious software packages to appeal to AI coding agents, while ‘slopsquatting’ shows the security risks of hallucinated dependencies.