The “Compatibility” Trap: New Mac Malware Tricks Users into Bypassing TCC
ID: cc07f401-f756-5d01-bac9-da33be94c43c
STIX ID: report--cc07f401-f756-5d01-bac9-da33be94c43c
Feed Name: securityonline.info
Darktrace uncovered a macOS phishing campaign that delivers an AppleScript file disguised as a Word document which displays a fake “Compatibility Wizard” prompt to socially engineer users into granting TCC permissions; the malware establishes persistence via LaunchAgents and deploys a modular Node.js loader that checks in with a C2 (sevrrhst.com) to retrieve and execute additional payloads, potentially enabling clandestine access to camera, screen capture, and other sensitive resources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
