Beware of New Compliance Emails Weaponizing Word/PDF Files to Steal Sensitive Data
ID: 8b97bac7-2221-58b9-9695-54438aa5d462
STIX ID: report--8b97bac7-2221-58b9-9695-54438aa5d462
Feed Name: cybersecurityNews.com
A sophisticated phishing campaign targets macOS users with fake audit/compliance emails and malicious AppleScript attachments (e.g., Confirmation_Token_Vesting.docx.scpt) that execute multi-stage, fileless payloads to harvest administrator credentials via convincing fake system prompts, inject into the macOS TCC privacy database to grant stealthy camera/screen/keyboard access for persistence, and establish a Node.js-based remote access backdoor; infrastructure includes the domain sevrrhst.com resolving to 88.119.171.59 and multiple throwaway domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
