Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Sapphire Sleet Targets macOS

83.136.208.48

TLP:CLEAR
Active

IPv4 Address

Description

We recently observed a multi-stage macOS intrusion campaign conducted by the North Korean state-sponsored threat group Sapphire Sleet (also tracked as BlueNoroff / UNC1069). The campaign specifically targets macOS environments within high-value financial sectors, including venture capital firms, Web3 developers, and cryptocurrency organizations. By leveraging signed, built-in system applications like the Apple Script Editor and Finder, the malware operates outside traditional macOS security enforcement boundaries, suppresses system security alerts, and executes arbitrary code directly under the guise of an authentic user update. This aligns with broader public reporting on macOS-focused intrusion tradecraft. Initial access relied on targeted social engineering in which victims were instructed to execute a fake Zoom SDK update component, leading to user-assisted execution and follow-on payload delivery.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Sapphire Sleet Targets macOS
Pattern Type
STIX
Confidence
75%
Valid From
May 29, 2026 21:09
Total Sightings
0
Added
May 29, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 83.136.208.48

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.