logo

Beware of New Compliance Emails Weaponizing Word/PDF Files to Steal Sensitive Data

ID: 8b97bac7-2221-58b9-9695-54438aa5d462

STIX ID: report--8b97bac7-2221-58b9-9695-54438aa5d462

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-03

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A sophisticated phishing campaign targets macOS users with fake audit/compliance emails and malicious AppleScript attachments (e.g., Confirmation_Token_Vesting.docx.scpt) that execute multi-stage, fileless payloads to harvest administrator credentials via convincing fake system prompts, inject into the macOS TCC privacy database to grant stealthy camera/screen/keyboard access for persistence, and establish a Node.js-based remote access backdoor; infrastructure includes the domain sevrrhst.com resolving to 88.119.171.59 and multiple throwaway domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.