Historical intelligence backfill. This assessment covers reporting originally published on 2026-04-16 and was added to the RWP archive on 2026-09-07.
Sapphire Sleet's macOS heist was a fake Zoom SDK in Script Editor, not a Gatekeeper bypass 0-day
DPRK actor Sapphire Sleet used recruiter lures and a compiled AppleScript named Zoom SDK Update.scpt so the victim ran the intrusion themselves.
Bottom line up front
CONFIRMED Microsoft's 16 April 2026 analysis of Sapphire Sleet (DPRK, crypto/finance/VC/blockchain targeting) shows a user-run macOS chain, not a Zoom or macOS CVE. Recruiter personas, fake technical interview, file Zoom SDK Update.scpt that opens in Script Editor. Decoy comment block looks like an SDK changelog. Then curl-to-osascript stages: recon, persistence (launch daemon / "services" backdoor), credential harvest, TCC tampering, wallets, browsers, keychain, Apple Notes, Telegram. A Mach-O host monitor posed as com.apple.cli. Microsoft shared with Apple; Apple added platform detections. A June 2026 Microsoft update on the same post describes a Teams-themed variant with the same user-driven model.
Historical backfill of 16 April 2026 reporting; added 7 September 2026.
What happened
Gatekeeper loses when the user presses Run. Script Editor is trusted. The Register and Computer Weekly match the Zoom-SDK filename and the "no vulnerability" line.
Why it mattered
Executive and developer Macs in crypto/finance are production wallets plus IdP sessions. Hiring-process malware is how DPRK has funded itself for years; this is the macOS kit.
Who / what was affected
Microsoft: crypto, finance, VC, blockchain targets. Exact victim count UNKNOWN.
Technical context
Block compiled AppleScript from untrusted downloads; MDM that prevents random launch daemons; separate browser for wallets; treat "update this SDK during the interview" as hostile.
Exploitation / threat status at the time
CONFIRMED social-engineering chain, Apple notified.
REPORTED June Teams-lure variant on the same Microsoft URL.
What defenders should have done
- Interview policy: no unsigned updates from the interviewer.
- Hunt
Zoom SDK Update.scpt, unexpected osascript/curl chains, fake com.apple.* launch daemons. - Rotate wallets and IdP from a known-clean device if the lure landed.
RWP assessment
Confidence: High on Microsoft's "user execution, not exploit" assessment.
Defensive actions
- MDM allow-list for Script Editor use.
- Recruiter-lure training for anyone who holds keys.
- Assume TCC prompts during an "interview" are the incident.
Sources
- Microsoft Threat Intelligence — Dissecting Sapphire Sleet’s macOS intrusion
- The Register — North Korea targets macOS users in latest heist
- Computer Weekly — North Korean social engineering campaign targets MacOS users