logo

macOS ClickFix attacks deliver AppleScript stealers to snarf credentials, wallets

ID: f25c5c22-e46a-52ee-9813-ebd7884b18a8

STIX ID: report--f25c5c22-e46a-52ee-9813-ebd7884b18a8

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-04-21

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Netskope observed an active ClickFix campaign targeting macOS users that uses a fake CAPTCHA and a Spotlight "paste" trick to execute a downloaded AppleScript infostealer. The malware forces victims to enter their system password via a persistent fake dialog, harvests macOS Keychain data, session tokens and cookies from 12 Chromium-based browsers plus Firefox/Waterfox, extracts data from 200+ browser extensions, and steals credentials from 16 desktop cryptocurrency wallets before staging data in /tmp/xdivcmp and exfiltrating it to a hardcoded C2; Netskope published related IoCs and scripts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.