New Clickfix Variant ‘Matryoshka’ Attacking Users to Deploy macOS Stealer Malware
ID: 9bb16767-d64e-52fb-b406-e8250415230d
STIX ID: report--9bb16767-d64e-52fb-b406-e8250415230d
Feed Name: cybersecurityNews.com
A sophisticated macOS social-engineering campaign called "Matryoshka" uses typosquatted domains and a ClickFix-style Terminal paste command to execute a nested, encoded payload that runs in memory. The multi-stage loader decodes and decompresses an AppleScript payload to harvest browser credentials and target crypto wallet apps (Trezor Suite, Ledger Live), employing evasion techniques such as heredoc-embedded payloads, detached background execution, suppressed I/O, and C2 checks that hinder automated scanners.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
