logo

New ClickFix Campaign Uses macOS Script Editor to Deliver Atomic Stealer

ID: 489db44a-bd3a-58eb-aec0-60c3fb64abae

STIX ID: report--489db44a-bd3a-58eb-aec0-60c3fb64abae

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-04-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A ClickFix campaign is targeting macOS users by invoking Script Editor via the applescript URL scheme from a fake Apple-branded webpage to bypass Terminal protections and run a pre-filled AppleScript that downloads and executes an Atomic Stealer infostealer; IOCs include domains (dryvecar.com, storage-fixes.squarespace.com, cleanupmac.mssg.me) and a Mach-O SHA-256 (3d3c91ee762668c85b74859e4d09a2adfd34841694493b82659fda77fe0c2c44).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.