Clickfix on macOS: AppleScript Stealer, Terminal Phishing, and C2 Infrastructure
ID: 0d49c858-58a9-55d7-8e38-e536163b51be
STIX ID: report--0d49c858-58a9-55d7-8e38-e536163b51be
Feed Name: Hunt.io Blog
**Executive summary:** This report details an ongoing Clickfix phishing campaign targeting macOS users that lures victims into pasting terminal commands (e.g., echo '...'+ | base64 -d | bash) which run AppleScript payloads to collect browser profiles, crypto wallets, documents, Keychain items, and other sensitive files, then package and exfiltrate them to attacker-controlled servers; the analysis includes payload behavior, infrastructure fingerprints (unusual ports, permissive CORS), hunting SQL queries, and enumerated IOCs for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
