logo

ClickFix technique uses Script Editor instead of Terminal on macOS

ID: 2f5a29d8-8ebe-5ab4-9abb-824e182f6e03

STIX ID: report--2f5a29d8-8ebe-5ab4-9abb-824e182f6e03

Feed Name: Jamf Blog

Threat Score
70/100

Date Published: 2026-04-02

Date Updated: 2026-07-16

...
...

Jamf Threat Labs describes a ClickFix-style macOS campaign that abuses the applescript:// URL scheme to open Script Editor with a pre-filled script, which downloads and executes an obfuscated payload that stages and runs an Atomic Stealer Mach-O binary; the report includes execution details, decoding methods, and IOCs (domain, URLs, filename and SHA256).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.