Historical intelligence backfill. This assessment covers reporting originally published on 2026-04-16 and was added to the RWP archive on 2026-09-07.

Daily Top · Nation-State

Sapphire Sleet's macOS heist was a fake Zoom SDK in Script Editor, not a Gatekeeper bypass 0-day

DPRK actor Sapphire Sleet used recruiter lures and a compiled AppleScript named Zoom SDK Update.scpt so the victim ran the intrusion themselves.

RWP Ventures · 2026-09-07 · event 2026-01-15 · 2 min read · priority 8.3

Bottom line up front

CONFIRMED Microsoft's 16 April 2026 analysis of Sapphire Sleet (DPRK, crypto/finance/VC/blockchain targeting) shows a user-run macOS chain, not a Zoom or macOS CVE. Recruiter personas, fake technical interview, file Zoom SDK Update.scpt that opens in Script Editor. Decoy comment block looks like an SDK changelog. Then curl-to-osascript stages: recon, persistence (launch daemon / "services" backdoor), credential harvest, TCC tampering, wallets, browsers, keychain, Apple Notes, Telegram. A Mach-O host monitor posed as com.apple.cli. Microsoft shared with Apple; Apple added platform detections. A June 2026 Microsoft update on the same post describes a Teams-themed variant with the same user-driven model.

Historical backfill of 16 April 2026 reporting; added 7 September 2026.

What happened

Gatekeeper loses when the user presses Run. Script Editor is trusted. The Register and Computer Weekly match the Zoom-SDK filename and the "no vulnerability" line.

Why it mattered

Executive and developer Macs in crypto/finance are production wallets plus IdP sessions. Hiring-process malware is how DPRK has funded itself for years; this is the macOS kit.

Who / what was affected

Microsoft: crypto, finance, VC, blockchain targets. Exact victim count UNKNOWN.

Technical context

Block compiled AppleScript from untrusted downloads; MDM that prevents random launch daemons; separate browser for wallets; treat "update this SDK during the interview" as hostile.

Exploitation / threat status at the time

CONFIRMED social-engineering chain, Apple notified.

REPORTED June Teams-lure variant on the same Microsoft URL.

What defenders should have done

  1. Interview policy: no unsigned updates from the interviewer.
  2. Hunt Zoom SDK Update.scpt, unexpected osascript/curl chains, fake com.apple.* launch daemons.
  3. Rotate wallets and IdP from a known-clean device if the lure landed.

RWP assessment

Confidence: High on Microsoft's "user execution, not exploit" assessment.

Defensive actions

  1. MDM allow-list for Script Editor use.
  2. Recruiter-lure training for anyone who holds keys.
  3. Assume TCC prompts during an "interview" are the incident.

Sources

  1. Microsoft Threat Intelligence — Dissecting Sapphire Sleet’s macOS intrusion
  2. The Register — North Korea targets macOS users in latest heist
  3. Computer Weekly — North Korean social engineering campaign targets MacOS users