Frequency
2
occurrences
First Seen
June 24, 2026
Last Seen
June 24, 2026
Related Threat Clusters
-
AppleScript-Driven macOS Intrusions Exploiting User Deception
Darktrace's Threat Research team identified a pattern of macOS intrusions leveraging ClickFix-style user deception. Attackers initiated the compromise through user-assisted execution of malicious updates, transitioning…
2 articles · Updated June 24, 2026
Recent Intelligence Reports
- From Click to Command: Behavioral Detection of AppleScript — Darktrace · June 24, 2026
- From Click to Command: Behavioral Detection of AppleScript — Darktrace · June 24, 2026
Related Entities
T1041 - Exfiltration Over C2 Channel
T1059.001 - PowerShell
T1059 - Command and Scripting Interpreter
T1071.001 - Web Protocols
T1071 - Application Layer Protocol
T1102 - Web Service
T1210 - Exploitation Of Remote Services
T1213.003 - Code Repositories
T1213 - Data From Information Repositories
T1505.003 - Web Shell
T1567.002 - Exfiltration to Cloud Storage
T1567 - Exfiltration Over Web Service