Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
North Korean Hackers Target macOS with AppleScript Attacks

North Korean Hackers Target macOS with AppleScript Attacks

Posted on April 22, 2026 By CWS

North Korean cyber attackers have intensified their focus on macOS users, employing advanced social engineering tactics. These recent assaults, which aim at individuals in financial sectors, highlight the hackers’ evolving strategies to bypass security measures and steal sensitive information.

Exploiting macOS Through Social Engineering

According to recent findings by Any.Run, a notorious method known as ClickFix has been integral to these attacks. This technique involves deceiving macOS users into installing malware designed to siphon off valuable data. The attackers, posing as trusted contacts on Telegram, send fake meeting invitations to business executives, urging them to resolve fabricated connectivity issues by executing specific commands in the Terminal.

This deception results in the execution of Go-based Mach-O binaries. These binaries are part of a comprehensive malware suite, coined Mach-O Man, that harvests user credentials, Keychain secrets, and browser session data, subsequently transmitting them via Telegram.

AppleScript and State-Sponsored Hacking

Another campaign, linked to the state-sponsored group Sapphire Sleet, is leveraging AppleScript for executing code and evading detection. This group, active since at least 2020 as identified by Microsoft, has similarly been focusing on extracting sensitive information from its targets.

In these attacks, the hackers impersonate recruiters on professional networks to initiate contact with victims. They then invite these individuals to fictitious technical interviews, during which they are tricked into installing malicious software disguised as legitimate video conferencing tools or software updates.

Complex Attack Chains and Data Exfiltration

The Sapphire Sleet campaign diverges from the ClickFix approach by automating the execution of malicious commands. The downloaded file, crafted as an AppleScript, opens within macOS’s Script Editor, executing embedded shell commands without user intervention.

This sophisticated infection chain involves multiple AppleScript payloads, ultimately deploying several backdoors. The attacks are designed to secure persistence and escalate privileges. These payloads perform extensive system reconnaissance, collecting data from applications, Telegram, browser profiles, Keychain, cryptocurrency wallets, and more.

These ongoing campaigns underscore the persistent threat posed by North Korean hackers, as they continue to refine their techniques to compromise high-value targets. With their ability to adapt and employ multiple attack vectors, these hackers remain a significant concern for cybersecurity experts worldwide.

Security Week News Tags:AppleScript, cyber attack, Cybersecurity, Hacking, information theft, macOS, Malware, North Korea, Sapphire Sleet, social engineering

Post navigation

Previous Post: Critical ASP.NET Core Vulnerability Patched by Microsoft
Next Post: Namastex npm Packages Compromised with CanisterWorm Malware

Related Posts

Adobe Patches Nearly 140 Vulnerabilities Adobe Patches Nearly 140 Vulnerabilities Security Week News
Critical Cisco ISE Vulnerabilities Allow Remote Code Execution  Critical Cisco ISE Vulnerabilities Allow Remote Code Execution  Security Week News
Intel and AMD Patch Over 80 Vulnerabilities in February Intel and AMD Patch Over 80 Vulnerabilities in February Security Week News
Hugging Face Abused to Deploy Android RAT Hugging Face Abused to Deploy Android RAT Security Week News
Artemis Unveils with M Funding Boost Artemis Unveils with $70M Funding Boost Security Week News
Bold Security Unveils  Million Funding Round Bold Security Unveils $40 Million Funding Round Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Mirai Botnet Exploits Vulnerability in Old D-Link Routers
  • Lotus Wiper Threatens Venezuela’s Energy Sector
  • Namastex npm Packages Compromised with CanisterWorm Malware
  • North Korean Hackers Target macOS with AppleScript Attacks
  • Critical ASP.NET Core Vulnerability Patched by Microsoft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Mirai Botnet Exploits Vulnerability in Old D-Link Routers
  • Lotus Wiper Threatens Venezuela’s Energy Sector
  • Namastex npm Packages Compromised with CanisterWorm Malware
  • North Korean Hackers Target macOS with AppleScript Attacks
  • Critical ASP.NET Core Vulnerability Patched by Microsoft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark