ClickFix campaign delivers Mac malware via fake Apple page
ID: 2c5aa040-503f-5229-a254-18c81cacb9ea
STIX ID: report--2c5aa040-503f-5229-a254-18c81cacb9ea
Feed Name: Help Net Security
Threat Score
Jamf researchers uncovered a ClickFix-style campaign that lures macOS users to a fake Apple-themed webpage which, after prompting to open Script Editor, pre-populates and executes a malicious script that downloads and runs an Atomic Stealer (AMOS) variant capable of exfiltrating Keychain items, browser credentials, cookies, autofill data and cryptocurrency wallet information; indicators of compromise were shared.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
