Atomic Stealer Malware Bypasses macOS Terminal Warnings Using Script Editor (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Attackers bypassed Apple's macOS 26.4 Terminal warnings by switching to Script Editor for ClickFix attacks.
- Atomic Stealer malware uses fraudulent ads to lure users into running malicious AppleScript code.
- The new technique undermines recent macOS security enhancements and requires user permission to succeed.
"Attackers behind the Atomic Stealer macOS malware have adapted their ClickFix technique to avoid Apple's new Terminal security warnings in macOS 26.4. Instead of instructing victims to paste commands into Terminal, they now use Script Editor, which lacks similar warnings. This shift allows the malware to continue tricking users into granting access permissions and exfiltrating data."
no comments yet.