Threats Tagged 'macos targeting'
View all threats tagged with 'macos targeting'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'macos targeting'
Click on any threat for detailed analysis and mitigation recommendations
From E-Sign to RMM: DocuSign Kit Targets Windows and... 0 A phishing campaign impersonates DocuSign to trick victims into installing legitimate remote management software such as MeshAgent, ScreenConnect, and SimpleHelp. It uses a reusable web kit with staged delivery, user-agent filtering targeting Windows systems (excluding Edge browsers), and Cloudflare Turnstile verification. The campaign features separate delivery paths for Windows and macOS, disables Windows Defender via VBS scripts, and establishes persistence through service installation. Active from May to July 2026, it rotates infrastructure across multiple domains to evade detection while abusing trusted IT tools for persistent access. Join the discussion | AlienVault OTX General | 07/21/2026, 11:38:33 UTC Added: 07/21/2026, 22:37:35 UTC |
Shared Claude Chats Meet ClickFix 0 A ClickFix campaign has been identified that abuses Anthropic's Claude platform through shareable chat links to distribute MacSync Stealer targeting macOS users. Attackers utilized malvertising with paid Google ads to direct victims searching for Claude-related terms to malicious shared Claude chats falsely labeled as 'Apple Support.' These chats contained obfuscated installation commands that, when executed, deployed a multi-stage infection chain. The malware steals credentials from browsers and password managers, cryptocurrency wallet data, sensitive files, and system information. The campaign ran from June 12-19, 2026, targeting primarily Mac users with Russian-language comments in the code suggesting Russian-speaking threat actors. Domains used adopted themes related to U.S. local services to appear legitimate. Join the discussion | AlienVault OTX General | 07/15/2026, 16:14:14 UTC Added: 07/15/2026, 22:03:24 UTC |
June 2026 Infostealer Trend Report 0 During June 2026, multiple infostealer families including Remus, ACRStealer, LummaC2, and Vidar were distributed through SEO poisoning techniques, disguised as illegal software such as cracks and keygens. Attacks utilized EXE files (84.5%) and DLL side-loading (15.5%) methods, with distribution primarily through Mediafire, Mega, and cloud storage platforms. Microsoft Corporation was the most frequently impersonated entity. MacOS environments were targeted through ClickFix techniques and malicious Bash scripts, with one variant dynamically obtaining C2 addresses via Polygon smart contracts. Email-based campaigns distributed AgentTesla and DarkCloud through compressed attachments, with both variants exfiltrating data via SMTP. The stolen credentials pose significant risks for dark web trading and secondary attacks. Join the discussion | AlienVault OTX General | 07/15/2026, 11:58:14 UTC Added: 07/15/2026, 21:47:49 UTC |
Showing 1 to 3 of 3 results