logo

Matryoshka Clickfix Variant Targets macOS Users, Deploys New Stealer Malware

ID: 1c9d1546-26d8-5427-b6bb-65a0de0103f3

STIX ID: report--1c9d1546-26d8-5427-b6bb-65a0de0103f3

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-02-16

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Matryoshka is a macOS-targeting evolution of the ClickFix social‑engineering campaign that uses typosquatting and a traffic distribution system to trick users into pasting a Terminal command which retrieves and in‑memory‑decompresses a Base64+gzip payload that ultimately executes an AppleScript stealer. The chain employs anti‑analysis measures (background detachment, I/O suppression, API‑gated C2, argument forwarding), targets browser credentials and cryptocurrency wallets (including Ledger Live and Trezor Suite), stages exfiltration to /tmp/osalogging.zip, and includes multiple IOCs and detection names.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.