Related Threat Clusters
-
North Korean Hackers Target Open Source Software Supply Chain via npm Packages
Amazon's threat intelligence has linked a series of compromises of popular npm packages—axios, debug, chalk, and typo-crypto—to a North Korean hacking group known as Sapphire Sleet. The group employed social engineering…
11 articles · Updated July 29, 2026 -
North Korean Sapphire Sleet Targets macOS Users in New Social Engineering Campaign
A North Korean cybercrime group known as Sapphire Sleet has launched a social engineering campaign targeting macOS users, as reported by Microsoft's Threat Intelligence unit. The campaign involves tricking users into…
7 articles · Updated April 17, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
751 articles · Updated April 29, 2026 -
PHANTOMPULSE Malware Campaign Exploits Obsidian for Targeted Attacks
A sophisticated social engineering campaign has been uncovered, targeting individuals in the financial and cryptocurrency sectors through the Obsidian note-taking application. The attackers, posing as representatives of…
9 articles · Updated April 14, 2026 -
MacSync Infostealer Exploits Google Search for Claude Installation
A malvertising campaign has emerged, using Google search results for Claude installation to deliver a macOS infostealer named MacSync. Victims are misled to a legitimate claude.ai shared conversation page, where they…
2 articles · Updated August 19, 2026 -
PamStealer: New macOS Infostealer Targets Users via Fake Maccy Manager
PamStealer is a newly identified macOS infostealer that masquerades as the legitimate Maccy clipboard manager. The malware employs a two-stage attack method, starting with a malicious AppleScript that downloads a…
86 articles · Updated July 3, 2026 -
AppleScript-Driven macOS Intrusions Exploiting User Deception
Darktrace's Threat Research team identified a pattern of macOS intrusions leveraging ClickFix-style user deception. Attackers initiated the compromise through user-assisted execution of malicious updates, transitioning…
2 articles · Updated June 24, 2026 -
CrowdStrike Enhances AI Security for Endpoints Amid Rising Threats
CrowdStrike announced new AI security features at RSA 2026, focusing on endpoint protection as AI applications proliferate. The Falcon platform now includes EDR AI Runtime Protection, which monitors commands and…
116 articles · Updated March 25, 2026 -
Infostealer Campaigns Expand to Target macOS Systems
Infostealer threats have shifted from primarily targeting Windows to macOS environments, as reported by the Microsoft Defender Security Research Team. Since late 2025, these campaigns have utilized cross-platform…
13 articles · Updated February 4, 2026 -
North Korean Hackers Use AI Deepfakes in Crypto Attacks
Google's Mandiant security team reported that North Korean hackers, identified as UNC1069 or 'CryptoCore', are employing AI-generated deepfakes in fraudulent video meetings to target cryptocurrency companies. The…
20 articles · Updated February 10, 2026
Recent Intelligence Reports
- MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer — Huntress · August 17, 2026
- Sapphire Sleet — cloud.google.com · August 4, 2026
- PamStealer is a new type of of macOS malware — Feeds.4Sysops · July 3, 2026
- New Mac infostealer confirms stolen passwords before stealing data — Appleinsider · July 2, 2026
- From Click to Command: Behavioral Detection of AppleScript — Darktrace · June 24, 2026
- From Click to Command: Behavioral Detection of AppleScript — Darktrace · June 24, 2026
- North Korean social engineering campaign targets macOS users — Computerweekly · April 17, 2026
- PhantomPulse RAT via Malicious Obsidian Vaults — Socprime · April 14, 2026