RST TI Report Digest: 11 May 2026
ID: 80fc46a5-ff41-520f-a112-93ea07b248fb
STIX ID: report--80fc46a5-ff41-520f-a112-93ea07b248fb
Feed Name: RST Cloud Blog
**ClickFix campaign uses fake macOS utilities lures to deliver infostealers** — Microsoft observed a macOS-targeted campaign that tricks users into running malicious shell commands to download and execute infostealers (SHub Stealer and AMOS); the malware harvests bash history, browser credentials, Keychain data and cryptocurrency wallet information, can persist via LaunchAgents, removes temporary traces, and the report includes extensive IOCs (IPs, domains, URLs, and SHA-256 hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
