THREAT OPS › Threat News › From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
<aside class="table-of-contents-block accordion wp-block-bloginabox-theme-table-of-contents" id="accordion-ee54ab46-434b-4523-bfb5-9dc49c0f3de1"> <button class="btn btn-collapse" type="button"> <span class="table-of-contents-block__label">In this article</span> <span class="table-of-contents-block__current"></span>
<svg class="table-of-contents-block__arrow" fill="none" height="11" viewBox
MITRE ATT&CK techniques
Indicators of compromise
- https://www.netskope.com/blog/macos-clickfix-lures-deploy-applescript-stealer-persistent-raturl
- https://pcapai.com/blog/amos-stealer-pcap-analysisurl
- https://www.sophos.com/en-us/blog/evil-evolution-clickfix-and-macos-infostealersurl
- https://microsoft.github.io/zerotrustassessment/url
- apricotfilepoint.comdomain
- lemonfilewave.comdomain
- limefilescope.comdomain
- mangocloudfile.comdomain
- applefilevault.comdomain
- bananafastfile.comdomain
- cloudfilebridge.comdomain
- filecedarwallet.onlinedomain
- filecrimsonsignal.onlinedomain
- orangesmartfile.comdomain
- syncdatavault.comdomain
- cloudsendhub.comdomain