Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'macos'

View all threats tagged with 'macos'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: macos

Threats Tagged 'macos'

Click on any threat for detailed analysis and mitigation recommendations

Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam
0

A sophisticated macOS malware campaign leverages ClickFix social engineering to infect victims. The attack begins with a fake CAPTCHA prompt delivered via email links, tricking users into executing malicious commands in Terminal. This downloads a profiling script that collects system information and deploys architecture-specific Go-based Mach-O payloads. The stealer targets browser passwords, Apple Keychain credentials, and cryptocurrency wallets. Its most notable feature is a DRAIN function that gradually siphons cryptocurrency from victims' wallets by redirecting portions to attacker-controlled accounts. The malware supports Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. Infrastructure analysis reveals hosting through Aeza Group, a sanctioned Russian bulletproof hosting provider. The malware achieves persistence through macOS Background Task Management and uses various evasion techniques including Gatekeeper bypass and credential harvesting via fake system prompts.

Join the discussion
ClickFix attack pushes macOS infostealer for crypto theft attacks
0

A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. [...]

Join the discussion
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
0

In this article Activity overview How ClickFix works Campaign overview ClickFix moved from open pages to fingerprinting gates The fingerprinting gate Mitigation and protection guidance Indicators of compromise (IOC) References Learn more Microsoft Threat Intelligence observed a macOS ClickFix campaign distributing infostealers, including MacSync and Atomic Stealer (AMOS) , through a large cluster of look-alike domains. The campaign evolved from broadly serving ClickFix lures to using a server-side browser-fingerprinting gate that shows the lure primarily to visitors whose environment appears consistent with a genuine macOS browser. This cloaking limits visibility for crawlers, sandboxes, and some automated analysis workflows. The blog details the domain pattern, fingerprinting checks, infection chain, detection coverage, and hunting pivots that defenders can use to identify related activity. Activity overview Microsoft Threat Intelligence has been tracking a macOS ClickFix operation that distributes information-stealing malware through a large family of algorithmically named domains. Over several weeks of monitoring, Microsoft observed a notable shift in tradecraft: the same infrastructure moved from openly serving the malicious command in the served page’s HTML source to concealing the lure behind a server-side fingerprinting gate that reveals the payload only to visitors the server assesses as a genuine macOS target. The chain ultimately delivers information stealers such as MacSync or Atomic Stealer (AMOS). This activity is consistent with the broader shift in macOS ClickFix tradecraft that Microsoft Threat Intelligence previously documented , in which threat actors instruct users to run Terminal commands that retrieve remotely hosted content rather than the traditional approach of delivering a disk image for manual installation. The cluster described here is notable for two reasons: its domains are mass-produced by a recognizable name generator, and it adopted server-side cloaking on existing infrastructure, giving defenders a clear before-and-after view of the same operation. In this blog, we describe the campaign’s domain-generation pattern, the two delivery phases we observed, the fingerprinting gate that now fronts the infrastructure, and the end-to-end infection chain. We also provide hunting guidance, mitigation recommendations, and defanged indicators of compromise. How ClickFix works ClickFix is a social-engineering technique where attackers persuade users to copy and run a command in Terminal instead of downloading a traditional macOS application. The lure usually appears as a fake verification step, software update, download error, or CAPTCHA, with the command disguised as something required to complete the action. Because execution starts from a user-run Terminal command rather than a downloaded app bundle, the flow can avoid parts of the normal macOS application trust path, including quarantine handling, code-signing evaluation, and notarization checks typically applied to downloaded applications. In this campaign, ClickFix remains the delivery mechanism, but the important change is that the lure is no longer shown to every visitor. The page first profiles the visitor through a browser-fingerprinting gate and primarily requests consistent with a genuine macOS browser environment receive the fake “Download for macOS” page and copied Terminal command. Figure 1a – The counterfeit “Download for macOS” page served to a qualifying visitor by a cloaked gate (apricotfilepoint[.]com). The page displays a forged “Verified Publisher” badge and offers a one-click Copy of an obfuscated curl one-liner. Delivery is conditional. During analysis, the same URLs returned different content to different requests. In some case the macOS ClickFix lure, and in others an apparently benign decoy page. In our testing, a request presenting a Windows browser received a decoy page such as a fake browser-extension or VPN landing page (Figure…

Join the discussion
Tenable Hexa AI: Automating exposure remediation with agentic routines
0

Discover how Tenable Hexa AI closes the gap between exposure management and endpoint patching using intent-driven routines, smart guardrails, and human approval. Key takeaways The problem: A slow handoff between security workflows creates a days-long remediation gap. The solution: Tenable Hexa AI bridges this gap using intent-driven Routines that automate scoping, deployment, and verification across integrated platforms like Jamf. Safety and control: Autonomy is governed by the harness built into Tenable One, ensuring the AI operates strictly within defined user permissions and guardrails. Find the exposure. Fix it. Confirm it is gone. Those three steps are rarely executed in a single place, by a single team. Exposure management knows which assets are at risk, while endpoint management actually changes the machine and applies the fix. Between those two domains of exposure identification and remediation lies a slow, manual handoff and multi-step routine that costs security teams days or weeks while vulnerabilities remain exposed: Scope the asset group Aim the remediation policy Execute patch deployment Check status Re-scan the environment to confirm the finding was closed. Tenable Hexa AI , the agentic engine of the Tenable One Exposure Management Platform , now spans that handoff, so you don’t have to manually toggle among tools or continually restart the conversation. How does Tenable Hexa AI autonomously close the remediation loop Say there’s an actively exploited Chrome vulnerability, and a fleet of your Macs is still running the vulnerable version. Rather than navigating multiple tools, you simply tell Tenable Hexa AI to patch it. Tenable Hexa AI executes the workflow in three unified stages: Enumeration and mapping - Tenable Hexa AI enumerates the affected assets across your exposure sources and resolves them to the devices your endpoint team already manages in Jamf. Policy identification - Tenable Hexa AI maps the CVE to the version that fixes it, then finds the Jamf patch definition that delivers that version. Proposal presentation - Before writing any changes, Tenable Hexa AI stops and shows you a proposal detailing the number of devices, which devices, what policy, and what the deployment window looks like. It highlights the blast radius and it tells you plainly that the action does not roll itself back. If you need to narrow enumeration to one business unit, just tell Hexa and it will re-scope and return a new plan before executing any changes. Once you approve, Tenable Hexa AI creates a static group in Jamf holding exactly the devices you approved, then triggers the policy against it. Ask Hexa for status at any point, and it returns the rollout device by device, without you leaving the chat window. Tenable Hexa AI then schedules a re-scan for after the patch deployment window. What previously took days across multiple tools now takes minutes within a single conversation, and all you need to do is make one decision rather than coordinate the manual execution of multiple, complex steps. Hand off recurring security work to intent-driven routines The ultimate goal of agentic AI for security is to help security teams efficiently and effectively scale cyber defense by taking on complex manual routines. To carry out vulnerability remediation and validation routines with Tenable Hexa AI, you define three core elements in plain, natural language: An objective - State what you are trying to achieve, in the words you would use with a colleague, not a sequence of steps (e.g., “Triage and patch critical vulnerabilities across MacOS endpoints”). Guardrails - Set explicit operational limits (e.g., “Never launch a credentialed scan against anything tagged OT,” or “Open no more than twenty-five tickets in a run”). A cadence - Choose whether to run the routine on demand or tell Hexa to run it on a specific schedule. Tenable Hexa AI drafts the plan using capabilities discovered from the tools you have already connected to Tenable One.…

HighExploit#macos
Join the discussion
New XCSSET variant targets macOS devs via compromised Xcode projects
0

A new variant of the XCSSET malware is targeting macOS developers by compromising Xcode projects and GitHub repositories. This malware campaign affects thousands of macOS users, specifically those involved in software development using Xcode. The attack vector involves injecting malicious code into legitimate development projects, potentially leading to unauthorized actions on infected systems.

Join the discussion
iPhone Users Urged to Update to Patch 2 Zero-Days
0

Two zero-day vulnerabilities affecting Apple devices running iOS 15 and macOS Monterey were actively exploited and patched in August 2022. One is a kernel out-of-bounds write flaw allowing arbitrary code execution with kernel privileges (CVE-2022-32894). The other is a WebKit out-of-bounds write vulnerability enabling code execution via malicious web content (CVE-2022-32893). Apple released patches in iOS 15.6.1 and macOS Monterey 12.5.1 to address these issues. Users were urged to update immediately due to active exploitation reports.

CriticalVulnerability#macos#ios
Join the discussion
New DOUBLECUP ClickFix service hides malware in browser cache images
0

A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. [...]

Join the discussion
CrashStealer, a new infostealer for macOS: how it works and how to stay safe | Kaspersky official blog
0

Mac users have historically trusted their operating system to keep them safe. That peace of mind mostly comes from Apple’s strict control over its ecosystem, and the fact that macOS has historically faced fewer mass attacks than Windows. However, that doesn’t mean Macs are invulnerable: threats do exist, and new ones emerge all the time. Over just the past few weeks, security researchers have published reports on at least two new campaigns that target Apple devices. The malware used in one of the campaigns has been dubbed CrashStealer , while the other is known as ClickLock . Both rely on different tricks to force users into entering their Mac password, which attackers then use to steal account credentials, crypto assets, documents, and much more. In today’s post, we take a close look at how CrashStealer operates — and how to avoid falling victim to it. A videoconferencing app with CrashStealer inside It was back in May 2026 that researchers spotted the first signs this malware was being developed, and by early July, they caught it operating in the wild. The malware earned its name because of its core mechanism: it disguises itself as the macOS built-in crash reporting tool (CrashReporter) while functioning as an infostealer designed to hijack sensitive data. Researchers managed to trace one of the websites users visited to download the malware. The site poses as a legitimate platform for distributing the video conferencing tool Werkbit. According to researchers, this is the site victims used to download Werkbit, which secretly contained the CrashStealer malware loader. Source However, you can’t just visit the site and download the software. Before downloading, visitors are asked to enter a special meeting PIN. This setup likely allows the attackers to limit the distribution scope by targeting only specific, pre-selected victims. Exactly how the cybercriminals choose their targets and deliver the PIN remains unknown. The “lucky” users with a code end up installing the initial malicious payload — named Werkbit Setup. Interestingly, it carries a valid Apple developer certificate and has successfully passed Apple’s notarization process — meaning it cleared the automated prescan for malicious code. As a result, the attackers manage to bypass the operating system’s built-in Gatekeeper defense. This allows the payload to launch without triggering the usual untrusted software warnings. The Werkbit Setup installer is signed with a valid Apple developer certificate and has passed notarization. Source Once launched, Werkbit Setup first reaches out to GitHub. Researchers believe using this popular platform helps attackers blend in by making these initial network requests look far less suspicious to security tools. After retrieving instructions from a GitHub repository, the program connects directly to the attackers’ server to fetch CrashStealer itself. The loader then saves the malware to a temporary macOS folder, launches it, and wipes most of the intermediate setup files. As a result, a fully functional infostealer is up and running within seconds of Werkbit Setup starting. By the way, the user never gets any videoconferencing app. How CrashStealer works Unlike the Werkbit Setup loader, the CrashStealer malware itself isn’t signed with an Apple developer certificate. To keep users from suspecting anything, the malware disguises itself as the built-in macOS crash reporting tool, CrashReporter, by using the exact same name, app identifier, and a similar icon. Once launched, CrashStealer completes a sequence of steps to gain access to sensitive data, establish persistence in the system, and cover its tracks: Remove metadata — including the attribute that flags the app as an internet download. Display a fake system prompt asking for the user’s macOS password. Use the previously captured credentials to gain access to Keychain, the built-in macOS password manager. Check the computer for installed security tools and malware analysis software.…

Join the discussion
A Deep Dive Into the Latest XCSSET Version
0

After months of dormancy, XCSSET malware version 40 emerged in April 2026 targeting macOS developers through supply chain attacks. The malware hides in Xcode projects of legitimate applications on GitHub, spreading through infected development environments. V40 features advanced detection evasion through polymorphic payload generation, fileless persistence, and in-memory execution while weakening security mechanisms. It introduces 17 distinct modules including a Chrome hijacking backdoor via Chrome DevTools Protocol and a Telegram trojanizer. The malware employs multi-layered encryption, disables system security updates, terminates cloud telemetry, and locks XProtect signature databases. Primary targeting focuses on developers across South Asia. The infrastructure utilizes approximately 40 domains registered in Russia and India, demonstrating a geographic pivot in operations.

Join the discussion
Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)
0

Introduction

Join the discussion

Showing 1 to 10 of 25 results

Filters:Tag: macos
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses