Darktrace AppleScript-Driven macOS Intrusions Exploiting User Deception
Article Content
- •Intrusions exploit user-assisted execution of malicious updates on macOS systems.
- •AppleScript is used for post-compromise activities, minimizing detection risks.
- •Automated responses successfully disrupted outbound communications in high-confidence cases.
Darktrace's Threat Research team identified a pattern of macOS intrusions leveraging ClickFix-style user deception. Attackers initiated the compromise through user-assisted execution of malicious updates, transitioning to AppleScript for post-compromise activities. The observed behaviors included HTTP POST requests to rare endpoints and unusual SSL properties, indicating command-and-control establishment. While individual indicators were low-confidence, the convergence of these signals across multiple environments suggested a structured attack. Automated containment measures were effective in halting outbound communications in high-confidence cases. This threat primarily affects macOS systems and emphasizes the need for behavioral detection strategies. The current status indicates ongoing monitoring and response efforts by security teams.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…