Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Dissecting macOS intrusion from lure to compromise

ur01webzoom.us

TLP:CLEAR
Active

Domain

Description

Microsoft Threat Intelligence uncovered a macOS-focused cyber campaign by North Korean threat actor Sapphire Sleet utilizing social engineering to compromise systems. The attack chain begins with a malicious AppleScript file disguised as a Zoom SDK update, which executes cascading payloads through curl-to-osascript chains. The campaign deploys multiple backdoors including com.apple.cli, services, icloudz, and com.google.chromes.updaters for persistence and command execution. Credential harvesting occurs through fake system dialogs that mimic legitimate macOS password prompts. The threat actor bypasses Transparency, Consent, and Control protections by directly manipulating the TCC database, enabling extensive data exfiltration targeting cryptocurrency wallets, browser credentials, Telegram sessions, SSH keys, and Apple Notes. Operations focus on cryptocurrency, finance, and blockchain organizations with the primary objective of stealing digital assets.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Dissecting macOS intrusion from lure to compromise
Pattern Type
STIX
Confidence
75%
Valid From
May 18, 2026 04:51
Total Sightings
0
Added
May 18, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of ur01webzoom.us

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.