logo

New Clickfix Variant ‘Matryoshka’ Attacking Users to Deploy macOS Stealer Malware

ID: 9bb16767-d64e-52fb-b406-e8250415230d

STIX ID: report--9bb16767-d64e-52fb-b406-e8250415230d

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-16

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A sophisticated macOS social-engineering campaign called "Matryoshka" uses typosquatted domains and a ClickFix-style Terminal paste command to execute a nested, encoded payload that runs in memory. The multi-stage loader decodes and decompresses an AppleScript payload to harvest browser credentials and target crypto wallet apps (Trezor Suite, Ledger Live), employing evasion techniques such as heredoc-embedded payloads, detached background execution, suppressed I/O, and C2 checks that hinder automated scanners.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.