logo

ClickFix Campaign Abuses macOS Script Editor to Deploy Atomic Stealer

ID: 7aa94315-772e-5a52-89e1-59748d5523c1

STIX ID: report--7aa94315-772e-5a52-89e1-59748d5523c1

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Jamf Threat Labs describes a refreshed ClickFix campaign that bypasses macOS Terminal paste protections by using applescript:// links to open Script Editor pre-populated with a fake “macOS Storage Optimization” script; executing it runs an obfuscated curl | zsh chain that fetches and executes a Mach-O binary (identified as an Atomic Stealer) from dryvecar.com. The report documents the delivery chain, decoding stages, runtime actions, and recommends blocking the AppleScript scheme, limiting Script Editor, and enabling Jamf Protect controls to detect and prevent the activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.