Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fake Software Updates Target macOS Users for Data Theft

Fake Software Updates Target macOS Users for Data Theft

Posted on June 17, 2026 By CWS

In a recent wave of cyber attacks, macOS users are being targeted by a sophisticated scheme that bypasses traditional software vulnerabilities. Instead of exploiting system flaws, hackers are employing deceptive tactics that manipulate unsuspecting users into compromising their own security.

Deceptive Tactics and Targets

The malicious campaign is orchestrated by Sapphire Sleet, a North Korean state-sponsored group active since March 2020. Their primary targets include individuals and organizations involved in cryptocurrency, venture capital, and the blockchain sector. The attackers’ main objective is to seize digital assets and sensitive financial details from high-value targets globally.

According to a report by Microsoft shared with Cyber Security News, this campaign began in early 2026, introducing new macOS-specific attack strategies not previously associated with this group. The attack relies on social engineering techniques, convincing users to execute harmful files themselves.

Execution of the Attack

The attack typically starts with victims being approached on social or professional media by individuals posing as recruiters. After building rapport, the victim is instructed to download a file masquerading as a Zoom SDK update. This file, once opened, deploys through macOS Script Editor, executing additional malicious codes unnoticed by the user.

Microsoft disclosed their findings to Apple, prompting the company to enhance security measures, including XProtect signature updates and Safari Safe Browsing blocks, to thwart this threat. Users are advised to ensure their systems are up-to-date to leverage these protections.

Internal Threat Mechanisms

Once the malicious script is activated, it launches a counterfeit application named systemupdate.app, which mimics a genuine macOS password request. Most users, thinking it legitimate, enter their credentials, which are then verified and sent to the attackers through Telegram.

Meanwhile, another fake application, softwareupdate.app, shows a convincing completion dialog to avoid arousing suspicion. The malware then gathers cryptocurrency wallet files, stored browser credentials, and other sensitive data, ensuring long-term access through persistent backdoors.

Defensive Measures and Recommendations

To counteract this threat, users should refrain from executing scripts or commands received via chat unless approved by trusted IT personnel. Organizations are encouraged to block downloaded AppleScript files and monitor for unauthorized changes to macOS databases. For cryptocurrency asset protection, using hardware wallets and regularly updating browser-stored credentials is advised.

Microsoft’s report highlights the importance of vigilance in the face of evolving cyber threats. By understanding the methods used by groups like Sapphire Sleet, macOS users can better safeguard their digital environments against these sophisticated attacks.

Cyber Security News Tags:Apple security, cryptocurrency theft, cyber attack methods, cybersecurity threat, fake software updates, macOS security, password theft, phishing attack, Sapphire Sleet, social engineering

Post navigation

Previous Post: Chrome, Firefox Updates Fix Critical Security Flaws
Next Post: Junior Hacker’s Persistent Access via OpenSSH and Tailscale

Related Posts

Windows 11 Enhances File Explorer with Speedy Menus Windows 11 Enhances File Explorer with Speedy Menus Cyber Security News
Hackers Exploit RTL/LTR Scripts and Browser Gaps to Hide Malicious URLs Hackers Exploit RTL/LTR Scripts and Browser Gaps to Hide Malicious URLs Cyber Security News
Critical cPanel Vulnerability Exploited by Hackers Critical cPanel Vulnerability Exploited by Hackers Cyber Security News
Hackers Infiltrated n8n’s Community Node Ecosystem With a Weaponized npm Package Hackers Infiltrated n8n’s Community Node Ecosystem With a Weaponized npm Package Cyber Security News
Critical Flaw in Cisco Secure Workload Exposes APIs Critical Flaw in Cisco Secure Workload Exposes APIs Cyber Security News
Vimeo Data Breach Exposes User Database Details Vimeo Data Breach Exposes User Database Details Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical cPanel Security Flaw in LiteSpeed Server Fixed
  • Homebrew 7.0.0 Unveils Vulnerability Scanner and Enhanced Security
  • Major Breach at Japan’s Digital Agency Exposes 240,000 Records
  • Critical Cisco Email Gateway Flaw Exploited, CISA Warns
  • Underground AI Service ‘Luciferus’ Promoted by Hackers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical cPanel Security Flaw in LiteSpeed Server Fixed
  • Homebrew 7.0.0 Unveils Vulnerability Scanner and Enhanced Security
  • Major Breach at Japan’s Digital Agency Exposes 240,000 Records
  • Critical Cisco Email Gateway Flaw Exploited, CISA Warns
  • Underground AI Service ‘Luciferus’ Promoted by Hackers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark