Sapphire Sleet is a apt_group tracked across 7 threat clusters and 16 intelligence report mentions on ThreatCluster. First observed October 31, 2025; most recent activity June 22, 2026.
A sophisticated malware campaign targeting macOS users has been linked to North Korean threat group Sapphire Sleet. This operation focuses on cryptocurrency organizations, venture capital firms, and Web3 developers.…
A North Korean cybercrime group known as Sapphire Sleet has launched a social engineering campaign targeting macOS users, as reported by Microsoft's Threat Intelligence unit. The campaign involves tricking users into…
A new cyber campaign targeting macOS users has been launched by the North Korean threat actor Sapphire Sleet. The attackers are distributing malware through a fake Zoom SDK update, tricking users into executing…
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
A new threat actor, JINX-0164, has been identified targeting cryptocurrency firms using custom macOS malware and social engineering tactics. Active since mid-2025, the group employs fake recruiter approaches to gain…
Hackers are actively targeting a command injection vulnerability, CVE-2023-33538, affecting several end-of-life TP-Link router models, including TL-WR940N and TL-WR841N. This vulnerability allows attackers to execute…
Google's Mandiant security team reported that North Korean hackers, identified as UNC1069 or 'CryptoCore', are employing AI-generated deepfakes in fraudulent video meetings to target cryptocurrency companies. The…