Threats · 132 days ago
Sapphire Sleet is turning the user, not the kernel, into the entry point. The group is using fake update and meeting lures to get macOS users to manually run malware, which bypasses built-in security checks and leaves credentials exposed even when the platform itself is not exploited.
Microsoft says the campaign targets Macs through decoy Zoom updates and other social engineering tied to fake recruiter outreach. The payload steals passwords, cryptocurrency assets, and sensitive data, and Microsoft says Apple has already pushed updates to detect and block the campaign’s infrastructure and malware.
The forward risk is simple. Any workflow that trains users to trust update prompts or support-style instructions can be turned into a delivery path for credential theft, especially in finance and technology environments where account access and crypto holdings are high-value targets.
9 sources covering this story
Supply-chain attacks take aim at your AI coding agents
A North Korean APT has crafted malicious software packages to appeal to AI coding agents, while ‘slopsquatting’ shows the security risks of hallucinated dependencies.
North Korean hackers trojanize gaming platform to spy on ethnic Koreans in China - Help Net Security
ScarCruft supply chain attack trojanized Windows and Android games on a Yanbian gaming platform to spy on ethnic Koreans since late 2024.
New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs
Claude Opus commit added malicious npm dependency in Feb 2026, enabling crypto theft and persistent RAT access.
North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures
Arctic Wolf attributed this large-scale spear-phishing campaign to BlueNoroff, a financially motivated subgroup of the Lazarus Group
North Korea-linked actor targets Web3 execs in social-engineering campaign
Founders and other top executives were compromised to gain access to crypto wallets.
North Korea's Lazarus Targets macOS Users via ClickFix
Lazarus continues leveraging ClickFix for initial access and data theft: in this case, against Mac-centric organizations and their high-value leaders.
North Korean Hackers Use AppleScript, ClickFix in Fresh macOS Attacks
The campaigns focus on financial organizations, including cryptocurrency, venture capital, and blockchain entities.
North Korea Uses ClickFix to Target macOS Users' Data
North Korea's Sapphire Sleet uses fake job offers and phony Zoom updates to deliver ClickFix attacks that steal credentials and sensitive data from Macs.
North Korea targets macOS users in latest heist
: Social engineering: 'low-cost, hard to patch, and scales well'
Dissecting Sapphire Sleet’s macOS intrusion from lure to compromise | Microsoft Security Blog
The Microsoft Defender Security Research Team uncovered a sophisticated macOS intrusion campaign attributed to the North Korean threat actor Sapphire Sleet that abuses user driven execution and social engineering to bypass macOS security protections and steal credentials, cryptocurrency assets, and sensitive data.
Part of the PlainSec briefing for 2026-05-05