logo

The “Compatibility” Trap: New Mac Malware Tricks Users into Bypassing TCC

ID: cc07f401-f756-5d01-bac9-da33be94c43c

STIX ID: report--cc07f401-f756-5d01-bac9-da33be94c43c

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-02-09

Date Updated: 2026-04-23

Author: Ddos

...
...

Darktrace uncovered a macOS phishing campaign that delivers an AppleScript file disguised as a Word document which displays a fake “Compatibility Wizard” prompt to socially engineer users into granting TCC permissions; the malware establishes persistence via LaunchAgents and deploys a modular Node.js loader that checks in with a C2 (sevrrhst.com) to retrieve and execute additional payloads, potentially enabling clandestine access to camera, screen capture, and other sensitive resources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.