PULSE NAME
Sapphire Sleet Targets macOS
WHITE AlienVault 2026-05-29 Modified: 2026-05-29
21
IOCs
MEDIUM VOLUME
We recently observed a multi-stage macOS intrusion campaign conducted by the North Korean state-sponsored threat group Sapphire Sleet (also tracked as BlueNoroff / UNC1069). The campaign specifically targets macOS environments within high-value financial sectors, including venture capital firms, Web3 developers, and cryptocurrency organizations. By leveraging signed, built-in system applications like the Apple Script Editor and Finder, the malware operates outside traditional macOS security enforcement boundaries, suppresses system security alerts, and executes arbitrary code directly under the guise of an authentic user update. This aligns with broader public reporting on macOS-focused intrusion tradecraft. Initial access relied on targeted social engineering in which victims were instructed to execute a fake Zoom SDK update component, leading to user-assisted execution and follow-on payload delivery.
Indicators of Compromise (21)
All FileHash-SHA256 domain IPv4
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 2075fd1a1362d188290910a8c55cf30c11ed5955c04af410c481410f538da419 2026-05-29
FileHash-SHA256 05e1761b535537287e7b72d103a29c4453742725600f59a34a4831eafc0b8e53 2026-05-29
FileHash-SHA256 5fbbca2d72840feb86b6ef8a1abb4fe2f225d84228a714391673be2719c73ac7 2026-05-29
FileHash-SHA256 5e581f22f56883ee13358f73fabab00fcf9313a053210eb12ac18e66098346e5 2026-05-29
FileHash-SHA256 95e893e7cdde19d7d16ff5a5074d0b369abd31c1a30962656133caa8153e8d63 2026-05-29
FileHash-SHA256 8fd5b8db10458ace7e4ed335eb0c66527e1928ad87a3c688595804f72b205e8c 2026-05-29
FileHash-SHA256 a05400000843fbad6b28d2b76fc201c3d415a72d88d8dc548fafd8bae073c640 2026-05-29
domain check02id.com 2026-05-29
domain uw04webzoom.us 2026-05-29
domain uw05webzoom.us 2026-05-29
domain uw03webzoom.us 2026-05-29
domain uv01webzoom.us 2026-05-29
domain uv03webzoom.us 2026-05-29
domain uv04webzoom.us 2026-05-29
domain ux06webzoom.us 2026-05-29
domain ur01webzoom.us 2026-05-29
IPv4 83.136.208.246 2026-05-29
IPv4 83.136.209.22 2026-05-29
IPv4 104.145.210.107 2026-05-29
IPv4 83.136.208.48 2026-05-29
IPv4 83.136.210.180 2026-05-29