A sophisticated macOS campaign exploits ClickFix social engineering, deceiving victims into executing malicious AppleScript commands via fake CAPTCHA verification pages. The attack chain deploys a persistent backdoor agent that utilizes EtherHiding, storing C2 addresses in Polygon blockchain smart contracts, making infrastructure detection challenging. The infection establishes persistence through LaunchAgents and deploys multiple payloads including the AMOS stealer targeting cryptocurrency wallets, browser credentials, and macOS Keychain data, alongside XMRig cryptominer for sustained revenue generation. The operation demonstrates advanced evasion through character-ID obfuscation, blockchain-based infrastructure, and abuse of legitimate macOS utilities. Analysis of blockchain transactions reveals complete C2 rotation history and funding trails, providing defenders with infrastructure-level pivots despite the campaign's memory-resident execution model.
Created: 2026-08-24
類似するPulseは見つかりませんでした。
このPulseに見つかったCVEはありません。