New macOS ClickFix attack silently mounts DMGs to push infostealer
ID: fd013aa3-6c5f-5bcd-8017-155494fbd974
STIX ID: report--fd013aa3-6c5f-5bcd-8017-155494fbd974
Feed Name: Bleeping Computer
Palo Alto Networks Unit 42 observed a macOS ClickFix campaign that lures victims into pasting Terminal commands to silently download, mount, and execute DMG-hosted Atomic macOS Stealer; the infostealer harvests browser credentials, authentication tokens, Keychain data, messaging app data, cryptocurrency wallets, and documents, stores results in a ZIP archive and uploads them to attacker-controlled servers (observed svs-verificationdate.beer and 196.251.107.171), and may replace legitimate Ledger Live and Trezor Suite installations to facilitate crypto theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
