Matryoshka Clickfix Variant Targets macOS Users, Deploys New Stealer Malware
ID: 1c9d1546-26d8-5427-b6bb-65a0de0103f3
STIX ID: report--1c9d1546-26d8-5427-b6bb-65a0de0103f3
Feed Name: GBHackers
Matryoshka is a macOS-targeting evolution of the ClickFix social‑engineering campaign that uses typosquatting and a traffic distribution system to trick users into pasting a Terminal command which retrieves and in‑memory‑decompresses a Base64+gzip payload that ultimately executes an AppleScript stealer. The chain employs anti‑analysis measures (background detachment, I/O suppression, API‑gated C2, argument forwarding), targets browser credentials and cryptocurrency wallets (including Ledger Live and Trezor Suite), stages exfiltration to /tmp/osalogging.zip, and includes multiple IOCs and detection names.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
