Technology

Microsoft experts warn North Korean attackers target macOS users with 'a highly reliable infection chain' to steal passwords, financial data and more — here's how to stay safe

2026-04-17 13:10
995 views
Microsoft experts warn North Korean attackers target macOS users with 'a highly reliable infection chain' to steal passwords, financial data and more — here's how to stay safe

A Lazarus spinoff is stirring trouble among companies, stealing crypto through fake jobs, Microsoft warns.

  1. Pro
  2. Security
Microsoft experts warn North Korean attackers target macOS users with 'a highly reliable infection chain' to steal passwords, financial data and more — here's how to stay safe News By Sead Fadilpašić published 17 April 2026

A Lazarus spinoff is stirring trouble among companies

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

North Korean flag made of binary code (Image credit: Shutterstock)
  • Copy link
  • Facebook
  • X
  • Whatsapp
  • Reddit
  • Pinterest
  • Flipboard
  • Threads
  • Email
Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Tech Radar Pro Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Become a Member in Seconds

Unlock instant access to exclusive member features.

Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

You are now subscribed

Your newsletter sign-up was successful

Join the club

Get full access to premium articles, exclusive features and a growing list of member rewards.

Explore An account already exists for this email address, please log in. Subscribe to our newsletter
  • Microsoft warns North Korean Sapphire Sleet (APT38) targeting Western businesses with fake job scams
  • Malicious Zoom lookalike drops infostealers to steal cryptocurrency
  • Campaign focuses on macOS users; Apple pushed automatic protections to block attacks

North Korean state-sponsored threat actors called Sapphire Sleet are targeting businesses in the west with infostealer malware in an attempt to nab their cryptocurrencies, experts have warned.

Security analysts from Microsoft said the group, also known as APT38, and most likely a spinoff from the infamous Lazarus Group, has been at it since at least 2020, and has employed one of the most successful techniques in its arsenal - fake jobs.

Sapphire Sleet would create a whole slew of fake, nonexistent things on social media: companies, recruiters, job ads, and anything else needed to make the scam look like a legitimate hiring attempt - with the victims are then approached, either via email or different social media channels, and offered the job (with enticing compensation offers).

Article continues below You may like
  • Hacker silhouette working on a laptop with North Korean flag on the background North Korean hackers target Microsoft Virtual Studio Code
  • North Korean flag with a hooded hacker North Korean hackers use AI-generated video to deliver malware for macOS and Windows
  • The Liquid Glass interface in macOS Tahoe. 'The prevailing wisdom used to be that macOS was at lower risk of malware infection compared to Windows...that’s no longer the case': Experts warn Mac infostealers are on the rise - here's how to stay safe

Attacking humans

During the process, however, the “recruiters” would ask the victim to join a Zoom video call, but the software used is not the real Zoom - instead, it is a fake, malicious version, designed to drop an infostealer on the device.

Speaking about the report, Sherrod DeGrippo, Microsoft global threat intelligence GM, told The Register why crooks focus on attacking the human, rather than the system: "Social engineering lets attackers route around hardened perimeters by convincing users to act on their behalf, turning a human into the vulnerability. It's low-cost, hard to patch, and scales well," DeGrippo explained.

"Users are conditioned to accept remote support interactions like downloading tools, following instructions, clicking prompts," she added. "Attackers exploit this familiarity to make malicious actions feel routine, lowering victim skepticism at the critical moment of compromise."

The campaign targets macOS users, it was said. Microsoft reached out to Apple, who added “platform-level protections” to help detect and block the malware and the infrastructure it uses. The updates were sent out automatically, meaning users need not update manually.

Are you a pro? Subscribe to our newsletterContact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsorsBy submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.Best antivirus software headerThe best antivirus for all budgetsOur top picks, based on real-world testing and comparisons

➡️ Read our full guide to the best antivirus1. Best overall:Bitdefender Total Security2. Best for families:Norton 360 with LifeLock3. Best for mobile:McAfee Mobile Security

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Sead FadilpašićSocial Links Navigation

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

View More

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Logout Read more Hacker silhouette working on a laptop with North Korean flag on the background Security North Korean hackers target Microsoft Virtual Studio Code    North Korean flag with a hooded hacker Security North Korean hackers use AI-generated video to deliver malware for macOS and Windows    The Liquid Glass interface in macOS Tahoe. Security 'The prevailing wisdom used to be that macOS was at lower risk of malware infection compared to Windows...that’s no longer the case': Experts warn Mac infostealers are on the rise - here's how to stay safe    IA y ciberseguridad Security 'macOS is becoming a more attractive target, and the tools attackers use are becoming more capable and more professional': Experts warn 'convincing' fake CleanMyMac installs target Apple users to empty crypto wallets    An image of macOS’s app switcher. Security Microsoft warns infostealer malware is 'rapidly expanding beyond traditional Windows-focused campaigns' and targeting Mac devices    Cryptocurrencies Security Linux users targeted as crypto-stealing malware hits Snap packages - here's how to stay safe    Latest in Security DDoS inscribed on a digital background made up of numbers Security Europol launches Operation PowerOFF — warns 75,000 DDoS users and takes down 53 domains    3D rendering of a section of an underwater internet communication cable on the seabed in the ocean Security China completes testing on tool capable of slicing undersea cables    FIFA World Cup Trophy is displayed during the FIFA World Cup 2026 Official Draw at John F. Kennedy Center for the Performing Arts on December 05, 2025 in Washington, DC. Security Experts warn FIFA World Cup partners could be putting customers at risk of email attacks    Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration Security This legit-looking software is actually antivirus-killing adware    Industrial geothermal power plant pipelines at sunset in Larderello, Tuscany region. Steam pipes and equipment for renewable energy production with dramatic pink sky. Security Russia hits European thermal power plant in attempted ‘destructive’ cyberattack    Someone using Excel on a Laptop. Security An ancient Microsoft Excel security flaw could let hackers hijack your entire system, so patch now    Latest in News TechDas Air Force IV turntable on a table, with TR's Money no Object badge in the top right corner Turntables ‘Your vinyl, vacuum-clamped’: this elite turntable makes your records float on air    The Insta360 GO Ultra camera held by a female photographer against a green wooded backdrop Mirrorless Cameras Insta360's first mirrorless camera leaked — and it's splitting opinion    Girl wearing Meta Quest 3 headset interacting with a jungle playset Virtual Reality & Augmented Reality Meta hikes Quest 3 and Quest 3S prices — and blames the RAM crisis    Sad gamer Storage & Backup More fake Samsung SSDs have been spotted – and CPU sales are slumping badly    007 First Light artwork featuring singer songwriter Lana Del Rey. Gaming 007 First Light has its own Bond theme by award-winning singer Lana Del Rey    ChatGPT coding Pro OpenAI takes major shot at Claude Code with major workplace updates    LATEST ARTICLES