ORO Hack Post-Mortem: The Sapphire Sleet Intrusion

2026-07-21 ORO

https://x.com/oroagents/status/2079371018880041257

Thumbnail for ORO Hack Post-Mortem: The Sapphire Sleet Intrusion

Sapphire Sleet used a compromised Telegram contact and a fake Microsoft Teams meeting to persuade an ORO team member to run a malicious AppleScript on macOS. The intrusion captured the system password, deployed a browser extension for keylogging, clipboard theft, screenshots, browser data collection, JavaScript injection, and remote command execution, and later established a persistent second-stage implant. The attacker ultimately stole the Bittensor SN15 owner wallet and sold 147,000 Alpha Tokens, while hardware-protected validator keys and other wallets and data remained unaffected. ORO attributes the operation with high confidence to the North Korean group based on overlap in the beaconing IP, payload, and infrastructure with Microsoft reporting, although the post does not disclose the indicator values.

Related Actors

Related Reports

« Back