Sapphire Sleet
2023-04-18 • Microsoft • How Microsoft names threat actors
Sapphire Sleet is a North Korean state actor that Microsoft named in April 2023 under its weather-themed taxonomy, replacing an earlier internal codename; Microsoft's naming reference also links it to Genie Spider and BlueNoroff. Microsoft has separately assessed the actor as active since at least March 2020, targeting the financial sector, including cryptocurrency, venture capital, and blockchain organizations, with the goal of stealing cryptocurrency wallets and related intellectual property. Its core playbook is social-engineering-led: operators create fake recruiter personas on social media and professional networking sites, engage targets about job opportunities, and direct them to install software disguised as video-conferencing tools or SDK updates. On macOS this has evolved into a multi-stage AppleScript intrusion chain using cascading script-to-interpreter payload delivery, fake system password dialogs to harvest credentials, manipulation of macOS permission databases to bypass user consent, and persistence mechanisms, culminating in exfiltration of browser data, cryptocurrency wallets, messaging-app sessions, SSH keys, and notes. The group has also run large-scale software-supply-chain compromises, including poisoning more than 140 npm packages with a typosquatted dependency that deployed a dropper and follow-on backdoors.
-
34
Related Actors
-
15
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster