Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign Targeting Cryptocurrency, Web3, and Venture Capital Sectors — Threadlinqs Intelligence
As of 2026-05-30, Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign Targeting Cryptocurrency, Web3, and Venture Capital Sectors is a high-severity malware threat attributed to APT38 (North Korea), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 31 indicators of compromise.
Threat ID: TL-2026-0383 · Severity: HIGH · CVSS: 8.1 · Status: ACTIVE · Category: MALWARE
Attribution: APT38 · North Korea · FINANCIAL
North Korean state-sponsored group Sapphire Sleet (aka BlueNoroff, TA444, COPERNICIUM, APT38 subcluster) is running an active macOS intrusion campaign against cryptocurrency exchanges, Web3 startups,
Sapphire Sleet — Microsoft's designation for the DPRK financially motivated cluster also tracked as BlueNoroff (Kaspersky), TA444 (Proofpoint), COPERNICIUM (legacy Microsoft), Stardust Chollima (CrowdStrike), and an APT38 offshoot — has expanded its macOS toolkit in a campaign running from early Q1 2026 into April 2026. Unlike prior BlueNoroff operations that relied heavily on weaponized Office documents, the 2026 wave favors native macOS binaries signed with stolen or fraudulently obtained Apple Developer IDs (revoked by Apple on 2026-04-13 following Microsoft's private disclosure).
Initial access begins with long-running social engineering operations on LinkedIn and Telegram, in which actors impersonate venture capitalists, crypto investors, or recruiters from legitimate firms (a16z, Paradigm, Sequoia Crypto, Binance Labs). After multi-week rapport-building, the target is invited to a fake investor meeting or receives a signed macOS application disguised as a PDF viewer, meeting-scheduling app, or NDA reviewer. Observed loader families include: RustBucket (a Rust-compiled stage-1 loader that retrieves a Mach-O from a remote server over HTTPS), KANDYKORN (a Python-orchestrated multi-stage implant first disclosed by Elastic Security in 2023, now observed with new anti-analysis checks including Virtualization.framework detection), ObjCShellz (an Objective-C reverse shell), and the newly named SwiftLoader (Swift-compiled dropper using NSURLSession over TLS 1.3).
Post-compromise tradecraft includes launch agent and launch daemon persistence (~/Library/LaunchAgents/com.apple.systempreferences.plist, /Library/LaunchDaemons/com.apple.softwareupdated.plist), AppleScript (osascript) execution for privilege elevation prompts that spoof system dialogs, macOS Keychain extraction via the security find-generic-password binary, and targeted theft of Chrome, Brave, Edge, and Arc browser extension data corresponding to MetaMask, Phantom, Trust Wallet, and Coinbase Wallet. Exfiltration uses HTTPS POSTs to actor-controlled infrastructure hosted predominantly on Stark Industries, FlokiNET, and low-reputation Russian hosters, with domains typosquatting venture capital and crypto firm names. Mandiant reports at least seven crypto firms confirmed compromised and losses exceeding 47 million USD attributable to this cluster in Q1 2026 alone, with proceeds assessed to fund DPRK weapons and missile programs per multiple UN Panel of Experts reports.
Defenders should treat unsolicited LinkedIn/Telegram recruiter and investor outreach to employees holding crypto wallet access or deployment keys as high-risk, enforce Gatekeeper and Developer ID verification checks, hunt for unexpected launch agents in user Library paths, and monitor for osascript spawning network child processes. CISA advisory AA26-104A provides sector-wide mitigations and mandates FCEB attestation of defensive controls for agencies with crypto or blockchain exposure by 2026-05-14.
Weaknesses (CWE)
CWE-506, CWE-494, CWE-287, CWE-798
Target sectors: cryptocurrency, web3, blockchain, venture_capital, financial_services, defi, fintech
Target regions: North America, Europe, East Asia, Southeast Asia, Middle East
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 31 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1589, T1598, T1583, T1585, T1588, T1587, T1566, T1566, T1204, T1059