Security

Sapphire Sleet macOS Intrusion: Key Defender Insights

3 min read

Summary

Microsoft Threat Intelligence detailed a macOS-focused campaign by Sapphire Sleet that uses social engineering and fake software updates instead of exploiting vulnerabilities. The attack chain relies on user-initiated AppleScript and Terminal execution to bypass native macOS protections, making layered defenses, user awareness, and endpoint detection especially important.

Need help with Security?Talk to an Expert

Introduction

Microsoft has published new research on a macOS intrusion campaign tied to Sapphire Sleet, a North Korean threat actor known for targeting cryptocurrency and finance organizations. The report matters because it shows how attackers can compromise Macs without using a software exploit—simply by convincing users to run what appears to be a legitimate update.

What’s new in this campaign

Microsoft observed Sapphire Sleet using a fake Zoom SDK Update.scpt file to start a multi-stage infection chain on macOS.

Key techniques highlighted

  • Social engineering over exploits: The campaign depends on users manually opening and running a malicious AppleScript file.
  • Trusted app abuse: The lure opens in macOS Script Editor, a legitimate Apple application, which helps the activity appear benign.
  • Multi-stage payload delivery: The script uses curl and osascript to fetch and run additional AppleScript payloads from attacker-controlled infrastructure.
  • Credential theft and persistence: Later stages harvest passwords, target cryptocurrency assets, manipulate TCC-related behavior, establish persistence, and exfiltrate sensitive data.
  • Decoy update workflow: The malicious script includes fake update instructions and launches trusted system tools to reinforce legitimacy.

Microsoft noted this attack chain can operate outside normal macOS security enforcement boundaries when execution is user-initiated, reducing the effectiveness of controls such as Gatekeeper, notarization checks, quarantine enforcement, and parts of the Transparency, Consent, and Control framework.

Why this matters for defenders

For IT and security teams, the main takeaway is that macOS users remain highly vulnerable to convincing lures, especially in high-value sectors like cryptocurrency, venture capital, finance, and blockchain. The campaign also shows that attackers are increasingly combining legitimate macOS utilities with staged payload delivery to avoid raising suspicion.

Organizations using Microsoft Defender should review Microsoft’s newly published detections, hunting guidance, and indicators of compromise for this activity. Cross-platform visibility is essential, particularly for environments that have historically treated Macs as lower-risk endpoints.

  • Educate users to avoid running unexpected update files, especially .scpt files or scripts delivered outside official channels.
  • Keep macOS up to date with Apple’s latest protections and security updates.
  • Review endpoint detections for suspicious use of Script Editor, osascript, and curl in sequence.
  • Hunt for fake update activity and abnormal AppleScript execution tied to external downloads.
  • Prioritize high-risk users in finance, crypto, and executive roles for stronger monitoring and phishing-resistant controls.

This research is a reminder that modern macOS attacks often succeed through persuasion, not exploitation. Security teams should combine user awareness, endpoint monitoring, and layered defense controls to reduce exposure.

Need help with Security?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Sapphire SleetmacOS securityMicrosoft Defendersocial engineeringcredential theft

Related Posts

Security

Microsoft Digital Defense Report 2026: Key Security Insights

Microsoft's 2026 Digital Defense Report highlights how AI and growing system interconnectedness are reshaping both cyberattacks and defense strategies. The report emphasizes that organizations must secure AI, identities, data, and cloud environments together while improving signal correlation across tools to detect modern threats faster.

Security

Government Cyber Risk in 2026: Microsoft’s 5 Priorities

Microsoft says government agencies were the most targeted sector in 2026, accounting for 27% of observed cyber threat activity. The company urges public-sector leaders to focus on five resilience priorities, including faster response, AI security, bidirectional information sharing, and planning for incidents that spread across suppliers and essential services.

Security

Microsoft Ignite 2026 Security Guide: Key Sessions

Microsoft has published its security guide for Microsoft Ignite 2026, highlighting AI-first security themes, a dedicated Security Pre-Day, and technical sessions focused on securing identities, data, devices, clouds, and AI agents. For IT and security teams, the event offers an early look at Microsoft’s roadmap and practical guidance for building an AI-ready security strategy.

Security

CVE-2026-73570: Zimbra Mail Server Exploitation

Microsoft is tracking active exploitation of CVE-2026-73570, an unauthenticated command injection flaw affecting internet-facing Zimbra mail servers with the optional zimbra-snmp package installed and SNMP notifications enabled. The issue can lead to web shell deployment, privilege escalation, mailbox data theft, and persistent remote access, making immediate patching and configuration review critical for administrators.

Security

Phishing Abuses RMM Tools for Persistent Access

Microsoft security researchers observed phishing campaigns in July 2026 that used a legitimate MSP360 RMM installer disguised as meeting invites, PDF updates, and other lures to gain remote access. Attackers then deployed ConnectWise ScreenConnect for redundant persistence, highlighting the need for tighter controls on remote management tools and better detection of unapproved RMM activity.

Security

Azure DevOps Attack Path Exposed in New DART Report

Microsoft’s latest DART cyberattack report shows how a single compromised identity was used to access Azure DevOps, alter pipelines, and harvest Kubernetes credentials. The case highlights how tightly connected identity, DevOps, and cloud environments can let attackers move far beyond source code, making stronger identity and pipeline controls essential.