ClickFix technique uses Script Editor instead of Terminal on macOS
ID: 2f5a29d8-8ebe-5ab4-9abb-824e182f6e03
STIX ID: report--2f5a29d8-8ebe-5ab4-9abb-824e182f6e03
Feed Name: Jamf Blog
Threat Score
Jamf Threat Labs describes a ClickFix-style macOS campaign that abuses the applescript:// URL scheme to open Script Editor with a pre-filled script, which downloads and executes an obfuscated payload that stages and runs an Atomic Stealer Mach-O binary; the report includes execution details, decoding methods, and IOCs (domain, URLs, filename and SHA256).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
