logo

Clickfix on macOS: AppleScript Stealer, Terminal Phishing, and C2 Infrastructure

ID: 0d49c858-58a9-55d7-8e38-e536163b51be

STIX ID: report--0d49c858-58a9-55d7-8e38-e536163b51be

Feed Name: Hunt.io Blog

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

**Executive summary:** This report details an ongoing Clickfix phishing campaign targeting macOS users that lures victims into pasting terminal commands (e.g., echo '...'+ | base64 -d | bash) which run AppleScript payloads to collect browser profiles, crypto wallets, documents, Keychain items, and other sensitive files, then package and exfiltrate them to attacker-controlled servers; the analysis includes payload behavior, infrastructure fingerprints (unusual ports, permissive CORS), hunting SQL queries, and enumerated IOCs for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.