New macOS stealer campaign uses Script Editor in ClickFix attack
ID: 225bbd16-b5a8-5d44-b097-24b93ed0e74d
STIX ID: report--225bbd16-b5a8-5d44-b097-24b93ed0e74d
Feed Name: Bleeping Computer
A campaign observed by security researchers uses malicious Apple-themed web pages and the applescript:// URL scheme to launch macOS Script Editor with prefilled code that runs an obfuscated 'curl | zsh' command, downloading and executing a Mach-O payload identified as Atomic Stealer (AMOS). The infostealer targets Keychain, browser cryptocurrency wallets, passwords, cookies and can include a backdoor for persistence; users are advised not to run Script Editor prompts from untrusted sources and to rely on official Apple guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
