logo

Malicious meeting invite fix targets Mac users

ID: 71eb60b1-e706-5bc3-a31b-045b4ed1ec33

STIX ID: report--71eb60b1-e706-5bc3-a31b-045b4ed1ec33

Feed Name: Malwarebytes Blog

Threat Score
65/100

Date Published: 2024-03-01

Date Updated: 2026-04-28

...
...

**Executive summary:** Cybercriminals are using Telegram DMs and fake calendar meeting links (often leveraging Calendly) to trick Mac users interested in cryptocurrency into running AppleScript (.scpt) files or applets that request administrator authentication and download a macOS Trojan; indicators include the .scpt extension, domains masquerading as meeting support, impersonation of crypto investors, and a bogus "regional access restriction" ruse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.