In November 2023, Microsoft's threat intelligence team disclosed a shift in tactics by Sapphire Sleet, a sub-cluster of North Korea's Lazarus Group also tracked as APT38, BlueNoroff, CageyChameleon, and CryptoCore. Rather than sending malicious links or attachments directly to targets, the group had started building its own fake skills-assessment and recruiting portals, aimed at IT job seekers and the recruiters who screen them.

The Mechanism

Sapphire Sleet typically identifies targets on LinkedIn using lures tied to skills assessments, then moves the conversation to other platforms once contact is made, according to Microsoft's public statements on the campaign. The fake portals require visitors to register an account and are password-protected specifically to make it harder for researchers to analyze. Anyone who downloads what's presented as an assessment tool receives malware instead.

Microsoft said the shift followed swift detection and takedown of the group's earlier malicious attachments, forcing it to build standalone infrastructure that blends in longer. The company reported it has already blocked a number of the domains tied to this campaign.

The macOS Connection

Around the same time, Jamf Threat Labs published research tying the group to a macOS malware family it calls ObjCShellz, a later-stage payload connected to an earlier BlueNoroff campaign called RustBucket. Jamf's write-up confirmed the payload runs on both Intel- and Arm-based Macs and functions as a remote shell deployed after initial access has already been gained through social engineering. RustBucket itself dates back to 2021 and has previously used fake recruiter and investor outreach to deliver backdoor malware capable of data theft and remote system control.

Who's Behind It

A 2022 joint Cybersecurity Advisory from the FBI, CISA, and the US Treasury Department, tracking a related North Korean operation called TraderTraitor, identifies Lazarus Group, APT38, BlueNoroff, and Stardust Chollima as names for the same state-sponsored actor. The advisory describes a long-running pattern of trojanized job and investment offers used to steal cryptocurrency, the same underlying playbook Sapphire Sleet's skills-assessment portals extend into a new delivery method.

Where It Stands

Sapphire Sleet's core motive, consistent with the rest of Lazarus's financially driven subgroups, is cryptocurrency theft rather than broader espionage. Job seekers and recruiters in tech and crypto-adjacent roles remain the primary targets, since access to a single compromised account or workstation can lead directly to wallets, exchange credentials, or a foothold inside an employer's network. Microsoft's continued domain takedowns and Jamf's ongoing tracking of the RustBucket and ObjCShellz malware families suggest the group is still active and adapting rather than shut down.

Sources

Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, and US Department of the Treasury, joint Cybersecurity Advisory AA22-108A, "TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies." cisa.gov/news-events/cybersecurity-advisories/aa22-108a

Federal Bureau of Investigation, Internet Crime Complaint Center, same advisory. ic3.gov/CSA/2022/220418.pdf

Jamf Threat Labs, "Jamf Threat Labs Discovers Malware from BlueNoroff." jamf.com/blog/bluenoroff-strikes-again-with-new-macos-malware

Jamf Threat Labs, "'RustBucket' malware targets macOS." jamf.com/blog/bluenoroff-apt-targets-macos-rustbucket-malware

The Hacker News, "Microsoft Warns of Fake Skills Assessment Portals Targeting IT Job Seekers," reporting on Microsoft Threat Intelligence's public disclosure of the campaign. thehackernews.com/2023/11/microsoft-warns-of-fake-skills.html