Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign Targeting Cryptocurrency, Web3, and Venture Capital Sectors

Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign (TL-2026-0383), also tracked as BlueNoroff macOS Crypto Campaign 2026, is a high-severity malware campaign scored CVSS 8.1, first published 2026-04-16. It is attributed to APT38 (North Korea) with high confidence, affects Apple macOS, maps to 27 MITRE ATT&CK techniques (T1005, T1027, T1041), and is covered by 9 detection rules and 31 indicators of compromise.

Key facts for TL-2026-0383

Threat ID
TL-2026-0383
Also known as
BlueNoroff macOS Crypto Campaign 2026, Operation RustDrop, SnatchCrypto 2026
Severity
HIGH
CVSS
8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L)
Status
ACTIVE
Category
MALWARE
First published
2026-04-16
Last reviewed
2026-04-16
Attribution
APT38
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
cryptocurrency, web3, blockchain, venture_capital, financial_services, defi, fintech
Target regions
North America, Europe, East Asia, Southeast Asia, Middle East
Detection rules
9
Indicators of compromise
31

Malware and tooling in Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign

Malware and tooling: KANDYKORN, ObjCShellz, RustBucket (OS X), SwiftLoader

North Korean state-sponsored group Sapphire Sleet (aka BlueNoroff, TA444, COPERNICIUM, APT38 subcluster) is running an active macOS intrusion campaign against cryptocurrency exchanges, Web3 startups, and venture capital firms. Operators pose as investors and recruiters on LinkedIn and Telegram, delivering signed Swift/Rust malware loaders (RustBucket, KANDYKORN, ObjCShellz, SwiftLoader) that abuse launch agents for persistence, dump the macOS Keychain, and exfiltrate cryptocurrency wallets. Microsoft, Mandiant, and CISA (AA26-104A) have confirmed active exploitation in April 2026.

How Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign works

Sapphire Sleet — Microsoft's designation for the DPRK financially motivated cluster also tracked as BlueNoroff (Kaspersky), TA444 (Proofpoint), COPERNICIUM (legacy Microsoft), Stardust Chollima (CrowdStrike), and an APT38 offshoot — has expanded its macOS toolkit in a campaign running from early Q1 2026 into April 2026. Unlike prior BlueNoroff operations that relied heavily on weaponized Office documents, the 2026 wave favors native macOS binaries signed with stolen or fraudulently obtained Apple Developer IDs (revoked by Apple on 2026-04-13 following Microsoft's private disclosure).

Initial access begins with long-running social engineering operations on LinkedIn and Telegram, in which actors impersonate venture capitalists, crypto investors, or recruiters from legitimate firms (a16z, Paradigm, Sequoia Crypto, Binance Labs). After multi-week rapport-building, the target is invited to a fake investor meeting or receives a signed macOS application disguised as a PDF viewer, meeting-scheduling app, or NDA reviewer. Observed loader families include: RustBucket (a Rust-compiled stage-1 loader that retrieves a Mach-O from a remote server over HTTPS), KANDYKORN (a Python-orchestrated multi-stage implant first disclosed by Elastic Security in 2023, now observed with new anti-analysis checks including Virtualization.framework detection), ObjCShellz (an Objective-C reverse shell), and the newly named SwiftLoader (Swift-compiled dropper using NSURLSession over TLS 1.3).

Post-compromise tradecraft includes launch agent and launch daemon persistence (~/Library/LaunchAgents/com.apple.systempreferences.plist, /Library/LaunchDaemons/com.apple.softwareupdated.plist), AppleScript (osascript) execution for privilege elevation prompts that spoof system dialogs, macOS Keychain extraction via the security find-generic-password binary, and targeted theft of Chrome, Brave, Edge, and Arc browser extension data corresponding to MetaMask, Phantom, Trust Wallet, and Coinbase Wallet. Exfiltration uses HTTPS POSTs to actor-controlled infrastructure hosted predominantly on Stark Industries, FlokiNET, and low-reputation Russian hosters, with domains typosquatting venture capital and crypto firm names. Mandiant reports at least seven crypto firms confirmed compromised and losses exceeding 47 million USD attributable to this cluster in Q1 2026 alone, with proceeds assessed to fund DPRK weapons and missile programs per multiple UN Panel of Experts reports.

Defenders should treat unsolicited LinkedIn/Telegram recruiter and investor outreach to employees holding crypto wallet access or deployment keys as high-risk, enforce Gatekeeper and Developer ID verification checks, hunt for unexpected launch agents in user Library paths, and monitor for osascript spawning network child processes. CISA advisory AA26-104A provides sector-wide mitigations and mandates FCEB attestation of defensive controls for agencies with crypto or blockchain exposure by 2026-05-14.

MITRE ATT&CK techniques used in TL-2026-0383

Collection

T1005 Data from Local System; T1560 Archive Collected Data

Defense Evasion

T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1497 Virtualization/Sandbox Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1573 Encrypted Channel

Persistence

T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

defense-impairment

T1553 Subvert Trust Controls

Credential Access

T1555 Credentials from Password Stores

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities

Reconnaissance

T1589 Gather Victim Identity Information; T1598 Phishing for Information

Impact

T1657 Financial Theft

Affected products and versions in Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign

  • Apple — macOS
    Vulnerable versions: Ventura 13.x; Sonoma 14.0-14.3; Sequoia 15.0-15.2
    Fixed in: Sonoma 14.4.1 (XProtect update); Sequoia 15.3 (XProtect update)
  • Google — Chrome browser extensions (MetaMask, Phantom)
    Vulnerable versions: all versions susceptible to credential theft by local malware
  • MetaMask — MetaMask browser extension
    Vulnerable versions: all versions - secrets stolen via on-disk vault file
  • Phantom — Phantom Wallet
    Vulnerable versions: all versions - secrets stolen via local storage

Remediation for Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign

Patches

  • Apply macOS Sonoma 14.4.1 or Sequoia 15.3 (contains updated XProtect Remediator signatures for RustBucket and KANDYKORN variants)
  • Update Jamf Protect to 6.12.0+ for dedicated Sapphire Sleet detection rules
  • Update CrowdStrike Falcon sensor for Mac to 7.19+ for IOA coverage of the campaign

Immediate actions

  • Block all indicators of compromise (IPs, domains, hashes) at perimeter, DNS, and EDR layers
  • Instruct employees with crypto, wallet, or deployment key access to reject unsolicited LinkedIn/Telegram investor or recruiter outreach and report to security
  • Revoke any macOS applications signed by Apple Developer IDs listed in Microsoft's April 2026 advisory and rotate any Keychain secrets on potentially exposed hosts
  • Force Gatekeeper and XProtect to latest signatures (xprotect update) across the fleet
  • Hunt for persistence artifacts in ~/Library/LaunchAgents and /Library/LaunchDaemons created in the last 90 days that reference unsigned or non-Apple binaries

Workarounds

  • Temporarily quarantine macOS endpoints that have executed any application signed by revoked Developer IDs pending forensic triage
  • Disable LinkedIn and Telegram on devices holding production signing keys where operationally feasible
  • Block AppleScript execution via MDM configuration profile (com.apple.applescript.disable) for non-engineering workstations

Longer-term hardening

  • Deploy EDR with macOS behavioral telemetry (Jamf Protect, CrowdStrike Falcon for Mac, SentinelOne) and enable full ES (EndpointSecurity) event collection
  • Enforce MDM policy to disable execution of unsigned applications and restrict Developer ID certificates to an allowlist
  • Require hardware security keys (YubiKey, Titan) for all crypto wallet, signing, and deployment approvals
  • Implement network egress filtering to block direct HTTPS from developer workstations to low-reputation ASNs (Stark Industries AS44477, FlokiNET AS200651) absent business justification
  • Conduct quarterly tabletop exercises simulating DPRK social engineering against finance and engineering staff

Weaknesses (CWE) in Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign

CWE-506, CWE-494, CWE-287, CWE-798

Timeline of Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign

  • BlueNoroff/Sapphire Sleet first publicly attributed as a financially motivated subcluster of DPRK's Lazarus Group, focused on SWIFT and crypto theft.
  • Kaspersky publishes SnatchCrypto report detailing BlueNoroff's long-running cryptocurrency startup targeting via weaponized Office documents.
  • Elastic Security Labs discloses KANDYKORN macOS implant attributed to DPRK, establishing the technical baseline later evolved in 2026.
  • Earliest telemetry of 2026 campaign: Microsoft observes first RustBucket variants bearing new Developer IDs and NSURLSession C2 code paths.
  • Mandiant reports a sharp uptick in LinkedIn and Telegram recruiter personas impersonating a16z, Paradigm, and Binance Labs contacting Web3 engineers.
  • First confirmed Q1 2026 intrusion at a North American DeFi firm; attackers exfiltrate MetaMask vault files and pivot to cloud signing keys.
  • Jamf Threat Labs identifies new SwiftLoader dropper family used alongside RustBucket in overlapping intrusions.
  • Microsoft publishes Sapphire Sleet macOS toolkit expansion advisory with IOCs and detection guidance.
  • Mandiant publishes corroborating BlueNoroff campaign tradecraft report including victim counts and financial loss estimates.
  • Apple revokes the fraudulent Developer ID certificates identified by Microsoft and pushes XProtect update with new signatures.
  • CISA issues Alert AA26-104A on DPRK targeting of the cryptocurrency sector with mitigations and FCEB attestation requirements.
  • Threadlinqs Intelligence publishes TL-2026-0383 consolidating vendor reporting, IOCs, MITRE mapping, and detection/simulation coverage.
  • CISA-mandated deadline for FCEB agencies with crypto or blockchain exposure to attest to AA26-104A mitigation implementation.
  • As of 2026-05-29, Sapphire Sleet/BlueNoroff remains an active DPRK threat: Microsoft's 2026-04-16 macOS report and later "Mach-O Man"/ClickFix reporting (CoinDesk 2026-04-22) tie the cluster to ongoing crypto intrusions and $500M+ Drift/KelpDAO losses. Apple's XProtect/Developer-ID revocations blunt specific samples but the state actor and social-engineering tradecraft persist.

Sources cited for Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign

Threats related to Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign

Detection coverage for TL-2026-0383

As of 2026-04-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0383 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats