macOS ClickFix attacks deliver AppleScript stealers to snarf credentials, wallets
ID: f25c5c22-e46a-52ee-9813-ebd7884b18a8
STIX ID: report--f25c5c22-e46a-52ee-9813-ebd7884b18a8
Feed Name: The Register (Security)
Netskope observed an active ClickFix campaign targeting macOS users that uses a fake CAPTCHA and a Spotlight "paste" trick to execute a downloaded AppleScript infostealer. The malware forces victims to enter their system password via a persistent fake dialog, harvests macOS Keychain data, session tokens and cookies from 12 Chromium-based browsers plus Firefox/Waterfox, extracts data from 200+ browser extensions, and steals credentials from 16 desktop cryptocurrency wallets before staging data in /tmp/xdivcmp and exfiltrating it to a hardcoded C2; Netskope published related IoCs and scripts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
