216.73.216.6

macOS ClickFix Campaign: AppleScript Stealers & New Terminal Protections

· Published 21/04/2026 02:05 · Modified 21/04/2026 09:28

Export JSON

Essential information

Published
21/04/2026 02:05
Modified
21/04/2026 09:28
Tags
2026-04-21 applescript browser data exfiltration clickfix credential harvesting cryptocurrency wallet theft infostealer macos session hijacking social engineering
Related entities
6 observables, 20 techniques (mitre), 3 others

Description

A sophisticated campaign targets both Windows and users through fake CAPTCHA pages that trick victims into executing malicious commands. The variant deploys an -based that harvests sensitive data including keychain databases, credentials, and session cookies from 12 browsers, over 200 browser extensions, and 16 cryptocurrency wallets. The malware employs a persistent, non-closable dialog box mimicking legitimate system prompts to force victims into providing their system password. Stolen session cookies enable attackers to bypass multi-factor authentication by hijacking active sessions. The campaign uses client-side JavaScript to filter victims by user-agent, directing desktop users to OS-specific payloads while ignoring mobile devices. Latest updates include native terminal security warnings designed to alert users against pasting potentially malicious commands.

External references