logo

Fake Compliance Emails Weaponize Word and PDF Attachments to Steal Sensitive Data

ID: 74116319-e2ed-5a95-b2fd-1f671e2c92d0

STIX ID: report--74116319-e2ed-5a95-b2fd-1f671e2c92d0

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-02-03

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Executive summary:** A phishing campaign targets macOS users with fake audit/compliance emails containing double-extension AppleScript attachments that deploy a fileless, multi-stage malware chain; the malware profiles systems, displays fake system-update prompts to harvest credentials, tampers with the TCC privacy database to grant broad permissions, establishes persistence and a Node.js-backed backdoor, and communicates with C2 infrastructure at sevrrhst.com (resolving to 88.119.171.59). The report includes filenames and SHA256 hashes, URLs, related domains and IPs as IOCs and recommends isolating affected hosts, resetting TCC permissions, terminating suspicious Node.js/script processes, and conducting a full incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.