Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign Targeting Cryptocurrency, Web3, and Venture Capital Sectors
Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign (TL-2026-0383), also tracked as BlueNoroff macOS Crypto Campaign 2026, is a high-severity malware campaign scored CVSS 8.1, first published 2026-04-16. It is attributed to APT38 (North Korea) with high confidence, affects Apple macOS, maps to 27 MITRE ATT&CK techniques (T1005, T1027, T1041), and is covered by 9 detection rules and 31 indicators of compromise.
Key facts for TL-2026-0383
- Threat ID
- TL-2026-0383
- Also known as
- BlueNoroff macOS Crypto Campaign 2026, Operation RustDrop, SnatchCrypto 2026
- Severity
- HIGH
- CVSS
- 8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L)
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-04-16
- Last reviewed
- 2026-04-16
- Attribution
- APT38
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- cryptocurrency, web3, blockchain, venture_capital, financial_services, defi, fintech
- Target regions
- North America, Europe, East Asia, Southeast Asia, Middle East
- Detection rules
- 9
- Indicators of compromise
- 31
Malware and tooling in Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign
Malware and tooling: KANDYKORN, ObjCShellz, RustBucket (OS X), SwiftLoader
North Korean state-sponsored group Sapphire Sleet (aka BlueNoroff, TA444, COPERNICIUM, APT38 subcluster) is running an active macOS intrusion campaign against cryptocurrency exchanges, Web3 startups, and venture capital firms. Operators pose as investors and recruiters on LinkedIn and Telegram, delivering signed Swift/Rust malware loaders (RustBucket, KANDYKORN, ObjCShellz, SwiftLoader) that abuse launch agents for persistence, dump the macOS Keychain, and exfiltrate cryptocurrency wallets. Microsoft, Mandiant, and CISA (AA26-104A) have confirmed active exploitation in April 2026.
How Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign works
Sapphire Sleet — Microsoft's designation for the DPRK financially motivated cluster also tracked as BlueNoroff (Kaspersky), TA444 (Proofpoint), COPERNICIUM (legacy Microsoft), Stardust Chollima (CrowdStrike), and an APT38 offshoot — has expanded its macOS toolkit in a campaign running from early Q1 2026 into April 2026. Unlike prior BlueNoroff operations that relied heavily on weaponized Office documents, the 2026 wave favors native macOS binaries signed with stolen or fraudulently obtained Apple Developer IDs (revoked by Apple on 2026-04-13 following Microsoft's private disclosure).
Initial access begins with long-running social engineering operations on LinkedIn and Telegram, in which actors impersonate venture capitalists, crypto investors, or recruiters from legitimate firms (a16z, Paradigm, Sequoia Crypto, Binance Labs). After multi-week rapport-building, the target is invited to a fake investor meeting or receives a signed macOS application disguised as a PDF viewer, meeting-scheduling app, or NDA reviewer. Observed loader families include: RustBucket (a Rust-compiled stage-1 loader that retrieves a Mach-O from a remote server over HTTPS), KANDYKORN (a Python-orchestrated multi-stage implant first disclosed by Elastic Security in 2023, now observed with new anti-analysis checks including Virtualization.framework detection), ObjCShellz (an Objective-C reverse shell), and the newly named SwiftLoader (Swift-compiled dropper using NSURLSession over TLS 1.3).
Post-compromise tradecraft includes launch agent and launch daemon persistence (~/Library/LaunchAgents/com.apple.systempreferences.plist, /Library/LaunchDaemons/com.apple.softwareupdated.plist), AppleScript (osascript) execution for privilege elevation prompts that spoof system dialogs, macOS Keychain extraction via the security find-generic-password binary, and targeted theft of Chrome, Brave, Edge, and Arc browser extension data corresponding to MetaMask, Phantom, Trust Wallet, and Coinbase Wallet. Exfiltration uses HTTPS POSTs to actor-controlled infrastructure hosted predominantly on Stark Industries, FlokiNET, and low-reputation Russian hosters, with domains typosquatting venture capital and crypto firm names. Mandiant reports at least seven crypto firms confirmed compromised and losses exceeding 47 million USD attributable to this cluster in Q1 2026 alone, with proceeds assessed to fund DPRK weapons and missile programs per multiple UN Panel of Experts reports.
Defenders should treat unsolicited LinkedIn/Telegram recruiter and investor outreach to employees holding crypto wallet access or deployment keys as high-risk, enforce Gatekeeper and Developer ID verification checks, hunt for unexpected launch agents in user Library paths, and monitor for osascript spawning network child processes. CISA advisory AA26-104A provides sector-wide mitigations and mandates FCEB attestation of defensive controls for agencies with crypto or blockchain exposure by 2026-05-14.
MITRE ATT&CK techniques used in TL-2026-0383
Collection
T1005 Data from Local System; T1560 Archive Collected Data
Defense Evasion
T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1497 Virtualization/Sandbox Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
Persistence
T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
defense-impairment
Credential Access
T1555 Credentials from Password Stores
Initial Access
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities
Reconnaissance
T1589 Gather Victim Identity Information; T1598 Phishing for Information
Impact
Affected products and versions in Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign
- Apple — macOS
Vulnerable versions: Ventura 13.x; Sonoma 14.0-14.3; Sequoia 15.0-15.2
Fixed in: Sonoma 14.4.1 (XProtect update); Sequoia 15.3 (XProtect update) - Google — Chrome browser extensions (MetaMask, Phantom)
Vulnerable versions: all versions susceptible to credential theft by local malware - MetaMask — MetaMask browser extension
Vulnerable versions: all versions - secrets stolen via on-disk vault file - Phantom — Phantom Wallet
Vulnerable versions: all versions - secrets stolen via local storage
Remediation for Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign
Patches
- Apply macOS Sonoma 14.4.1 or Sequoia 15.3 (contains updated XProtect Remediator signatures for RustBucket and KANDYKORN variants)
- Update Jamf Protect to 6.12.0+ for dedicated Sapphire Sleet detection rules
- Update CrowdStrike Falcon sensor for Mac to 7.19+ for IOA coverage of the campaign
Immediate actions
- Block all indicators of compromise (IPs, domains, hashes) at perimeter, DNS, and EDR layers
- Instruct employees with crypto, wallet, or deployment key access to reject unsolicited LinkedIn/Telegram investor or recruiter outreach and report to security
- Revoke any macOS applications signed by Apple Developer IDs listed in Microsoft's April 2026 advisory and rotate any Keychain secrets on potentially exposed hosts
- Force Gatekeeper and XProtect to latest signatures (xprotect update) across the fleet
- Hunt for persistence artifacts in ~/Library/LaunchAgents and /Library/LaunchDaemons created in the last 90 days that reference unsigned or non-Apple binaries
Workarounds
- Temporarily quarantine macOS endpoints that have executed any application signed by revoked Developer IDs pending forensic triage
- Disable LinkedIn and Telegram on devices holding production signing keys where operationally feasible
- Block AppleScript execution via MDM configuration profile (com.apple.applescript.disable) for non-engineering workstations
Longer-term hardening
- Deploy EDR with macOS behavioral telemetry (Jamf Protect, CrowdStrike Falcon for Mac, SentinelOne) and enable full ES (EndpointSecurity) event collection
- Enforce MDM policy to disable execution of unsigned applications and restrict Developer ID certificates to an allowlist
- Require hardware security keys (YubiKey, Titan) for all crypto wallet, signing, and deployment approvals
- Implement network egress filtering to block direct HTTPS from developer workstations to low-reputation ASNs (Stark Industries AS44477, FlokiNET AS200651) absent business justification
- Conduct quarterly tabletop exercises simulating DPRK social engineering against finance and engineering staff
Weaknesses (CWE) in Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign
CWE-506, CWE-494, CWE-287, CWE-798
Timeline of Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign
- BlueNoroff/Sapphire Sleet first publicly attributed as a financially motivated subcluster of DPRK's Lazarus Group, focused on SWIFT and crypto theft.
- Kaspersky publishes SnatchCrypto report detailing BlueNoroff's long-running cryptocurrency startup targeting via weaponized Office documents.
- Elastic Security Labs discloses KANDYKORN macOS implant attributed to DPRK, establishing the technical baseline later evolved in 2026.
- Earliest telemetry of 2026 campaign: Microsoft observes first RustBucket variants bearing new Developer IDs and NSURLSession C2 code paths.
- Mandiant reports a sharp uptick in LinkedIn and Telegram recruiter personas impersonating a16z, Paradigm, and Binance Labs contacting Web3 engineers.
- First confirmed Q1 2026 intrusion at a North American DeFi firm; attackers exfiltrate MetaMask vault files and pivot to cloud signing keys.
- Jamf Threat Labs identifies new SwiftLoader dropper family used alongside RustBucket in overlapping intrusions.
- Microsoft publishes Sapphire Sleet macOS toolkit expansion advisory with IOCs and detection guidance.
- Mandiant publishes corroborating BlueNoroff campaign tradecraft report including victim counts and financial loss estimates.
- Apple revokes the fraudulent Developer ID certificates identified by Microsoft and pushes XProtect update with new signatures.
- CISA issues Alert AA26-104A on DPRK targeting of the cryptocurrency sector with mitigations and FCEB attestation requirements.
- Threadlinqs Intelligence publishes TL-2026-0383 consolidating vendor reporting, IOCs, MITRE mapping, and detection/simulation coverage.
- CISA-mandated deadline for FCEB agencies with crypto or blockchain exposure to attest to AA26-104A mitigation implementation.
- As of 2026-05-29, Sapphire Sleet/BlueNoroff remains an active DPRK threat: Microsoft's 2026-04-16 macOS report and later "Mach-O Man"/ClickFix reporting (CoinDesk 2026-04-22) tie the cluster to ongoing crypto intrusions and $500M+ Drift/KelpDAO losses. Apple's XProtect/Developer-ID revocations blunt specific samples but the state actor and social-engineering tradecraft persist.
Sources cited for Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign
- Microsoft: Sapphire Sleet Expands macOS Toolkit Against Crypto Sector
- Mandiant: BlueNoroff macOS Campaign Tradecraft Update
- CISA Alert AA26-104A: DPRK Targeting of Cryptocurrency Sector
- Elastic Security Labs: KANDYKORN Technical Analysis (historical baseline)
- Jamf Threat Labs: RustBucket Evolution and Hunting Guide 2026
- Kaspersky SecureList: BlueNoroff SnatchCrypto campaign overview
- UN Panel of Experts Report S/2024/215 on DPRK sanctions evasion via crypto theft
- US Treasury OFAC designation of Lazarus Group and affiliated DPRK operators
- MITRE ATT&CK Group: BlueNoroff (G0098)
- SentinelOne: Hunting macOS Malware with Launch Agent and Daemon Telemetry
Threats related to Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign
- Void Dokkaebi (Famous Chollima) Cython-Compiled InvisibleFerret — .pyd/.so Binary Evasion of Script-Based Detections (DPRK Contagious Interview)
- Omnistealer: DPRK-Linked Blockchain-Based Infostealer Abusing TRON/Aptos/BSC as Resilient C2 to Loot Password Managers, Browser Credentials, Cloud Storage, and 60+ Crypto Wallets
- Cross-Platform Node.js NPM Stealer — Browser Credentials, Sensitive File Exfiltration, and WebSocket Reverse Shell (SHA256 049300aa…ddeb9, C2 216.126.225.243)
Detection coverage for TL-2026-0383
As of 2026-04-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0383 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.