logo

macOS ClickFix AppleScript Stealer Hijacks Crypto Wallets

ID: 1e17b136-af97-5715-b54a-a62a5f3dae78

STIX ID: report--1e17b136-af97-5715-b54a-a62a5f3dae78

Feed Name: securityonline.info

Threat Score
76/100

Date Published: 2026-06-23

Date Updated: 2026-06-23

Author: Do Son

...
...

### Executive Summary Netskope Threat Labs identified 'Meow', an AppleScript-based macOS infostealer/RAT active since May 2026 that uses fake troubleshooting sites and clipboard-manipulation to achieve in-memory, fileless execution; it harvests browser credentials, session cookies, messaging tokens, and cryptocurrency wallet data (including replacing wallet apps), maintains C2-based persistence, and targets macOS users across multiple regions. Recommended defenses include blocking malicious lure domains, monitoring terminal/clipboard activity, checking for unusual launch daemons (e.g., com.apple.accountsd), and reinstalling wallet software from official sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.