216.73.217.22

Clickfix on macOS: AppleScript Stealer, Terminal Phishing, and C2 Infrastructure

· Published 22/08/2025 17:35 · Modified 25/08/2025 11:32

Export JSON

Essential information

Published
22/08/2025 17:35
Modified
25/08/2025 11:32
Tags
2025-08-22 applescript c2 infrastructure clickfix cryptowallet data theft macos phishing terminal commands
Related entities
8 techniques (mitre), 1 malware, 2 others

Description

A sophisticated campaign targeting users employs a technique called , which tricks victims into running that execute malicious . This script steals sensitive data including browser profiles, crypto wallets, and personal files. The attackers use fake security prompts and CAPTCHA pages on domains like cryptoinfo-news.com to appear legitimate. The stolen data is exfiltrated to command and control servers, some of which run on unusual ports. The campaign's infrastructure spans multiple regions, with several C2 servers hosted in Russia. The analysis uncovered over 50 related servers with similar configurations, suggesting a financially motivated and globally distributed operation.

External references