macOS Users Become the Weak Link in Fake Updates

Sapphire Sleet is turning the user, not the kernel, into the entry point. The group is using fake update and meeting lures to get macOS users to manually run malware, which bypasses built-in security checks and leaves credentials exposed even when the platform itself is not exploited. Microsoft says the campaign targets Macs through decoy Zoom updates and other social engineering tied to fake recruiter outreach. The payload steals passwords, cryptocurrency assets, and sensitive data, and Microsoft says Apple has already pushed updates to detect and block the campaign’s infrastructure and malware. The forward risk is simple. Any workflow that trains users to trust update prompts or support-style instructions can be turned into a delivery path for credential theft, especially in finance and technology environments where account access and crypto holdings are high-value targets.

Part of the PlainSec briefing for 2026-05-05

Sources