Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign

2026-05-28 Levelblue

https://www.levelblue.com/blogs/spiderlabs-blog/sapphire-sleet-targets-macos-in-multi-stage-intrusion-campaign

Thumbnail for Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign

Sapphire Sleet, also tracked as BlueNoroff and UNC1069, is targeting macOS users in venture capital, Web3, and cryptocurrency organizations through social engineering that delivers a fake Zoom SDK update. The infection chain uses Script Editor, `osascript`, `curl`, and shell commands, then deploys a fake macOS password prompt, abuses Finder and TCC.db to grant automation permissions, and persists through a LaunchDaemon that loads an in-memory beacon. The malware collects cryptocurrency wallets, browser extension data, Telegram sessions, SSH keys, and Apple Notes, then stages archives for upload and exfiltration. Although some original infrastructure was likely mitigated, the native-binary abuse, TCC manipulation, and LaunchDaemon persistence remain durable detection opportunities.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ur01webzoom.us 2026-05-28 2026-05-28
DOMAIN ux06webzoom.us 2026-05-28 2026-05-28
DOMAIN uv04webzoom.us 2026-05-28 2026-05-28
DOMAIN uv03webzoom.us 2026-05-28 2026-05-28
DOMAIN uv01webzoom.us 2026-05-28 2026-05-28
DOMAIN uw03webzoom.us 2026-05-28 2026-05-28
DOMAIN uw05webzoom.us 2026-05-28 2026-05-28
DOMAIN uw04webzoom.us 2026-05-28 2026-05-28
IPv4 83.136.210.180 2026-04-16 2026-04-27
DOMAIN check02id.com 2026-04-16 2026-04-27
IPv4 83.136.209.22 2026-04-16 2026-04-27
IPv4 83.136.208.246 2026-04-16 2026-04-27
IPv4 104.145.210.107 2026-04-16 2026-04-27
HASH 5fbbca2d72840feb86b6ef8a1abb4fe… 2026-04-16 2026-04-16
HASH 8fd5b8db10458ace7e4ed335eb0c665… 2026-04-16 2026-04-16
HASH 05e1761b535537287e7b72d103a29c4… 2026-04-16 2026-04-16
HASH 5e581f22f56883ee13358f73fabab00… 2026-04-16 2026-04-16
HASH 95e893e7cdde19d7d16ff5a5074d0b3… 2026-04-16 2026-04-16
HASH a05400000843fbad6b28d2b76fc201c… 2026-04-16 2026-04-16
HASH 2075fd1a1362d188290910a8c55cf30… 2026-04-16 2026-04-16
IPv4 83.136.208.48 2026-04-16 2026-04-16

Related Actors

Related Reports

« Back