ClickFix Campaign Abuses macOS Script Editor to Deploy Atomic Stealer
ID: 7aa94315-772e-5a52-89e1-59748d5523c1
STIX ID: report--7aa94315-772e-5a52-89e1-59748d5523c1
Feed Name: GBHackers
Jamf Threat Labs describes a refreshed ClickFix campaign that bypasses macOS Terminal paste protections by using applescript:// links to open Script Editor pre-populated with a fake “macOS Storage Optimization” script; executing it runs an obfuscated curl | zsh chain that fetches and executes a Mach-O binary (identified as an Atomic Stealer) from dryvecar.com. The report documents the delivery chain, decoding stages, runtime actions, and recommends blocking the AppleScript scheme, limiting Script Editor, and enabling Jamf Protect controls to detect and prevent the activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
