Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign
2026-05-28 • Levelblue •
Sapphire Sleet, also tracked as BlueNoroff and UNC1069, is targeting macOS users in venture capital, Web3, and cryptocurrency organizations through social engineering that delivers a fake Zoom SDK update. The infection chain uses Script Editor, `osascript`, `curl`, and shell commands, then deploys a fake macOS password prompt, abuses Finder and TCC.db to grant automation permissions, and persists through a LaunchDaemon that loads an in-memory beacon. The malware collects cryptocurrency wallets, browser extension data, Telegram sessions, SSH keys, and Apple Notes, then stages archives for upload and exfiltration. Although some original infrastructure was likely mitigated, the native-binary abuse, TCC manipulation, and LaunchDaemon persistence remain durable detection opportunities.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | ur01webzoom.us | 2026-05-28 | 2026-05-28 |
| DOMAIN | ux06webzoom.us | 2026-05-28 | 2026-05-28 |
| DOMAIN | uv04webzoom.us | 2026-05-28 | 2026-05-28 |
| DOMAIN | uv03webzoom.us | 2026-05-28 | 2026-05-28 |
| DOMAIN | uv01webzoom.us | 2026-05-28 | 2026-05-28 |
| DOMAIN | uw03webzoom.us | 2026-05-28 | 2026-05-28 |
| DOMAIN | uw05webzoom.us | 2026-05-28 | 2026-05-28 |
| DOMAIN | uw04webzoom.us | 2026-05-28 | 2026-05-28 |
| IPv4 | 83.136.210.180 | 2026-04-16 | 2026-04-27 |
| DOMAIN | check02id.com | 2026-04-16 | 2026-04-27 |
| IPv4 | 83.136.209.22 | 2026-04-16 | 2026-04-27 |
| IPv4 | 83.136.208.246 | 2026-04-16 | 2026-04-27 |
| IPv4 | 104.145.210.107 | 2026-04-16 | 2026-04-27 |
| HASH | 5fbbca2d72840feb86b6ef8a1abb4fe… | 2026-04-16 | 2026-04-16 |
| HASH | 8fd5b8db10458ace7e4ed335eb0c665… | 2026-04-16 | 2026-04-16 |
| HASH | 05e1761b535537287e7b72d103a29c4… | 2026-04-16 | 2026-04-16 |
| HASH | 5e581f22f56883ee13358f73fabab00… | 2026-04-16 | 2026-04-16 |
| HASH | 95e893e7cdde19d7d16ff5a5074d0b3… | 2026-04-16 | 2026-04-16 |
| HASH | a05400000843fbad6b28d2b76fc201c… | 2026-04-16 | 2026-04-16 |
| HASH | 2075fd1a1362d188290910a8c55cf30… | 2026-04-16 | 2026-04-16 |
| IPv4 | 83.136.208.48 | 2026-04-16 | 2026-04-16 |