PULSE NAME
AppleScript Abuse: Unpacking a macOS Phishing Campaign
WHITE PetrP.73 2026-02-07 Modified: 2026-03-09
25
IOCs
MEDIUM VOLUME
A recent malware campaign targeting macOS users has been identified, leveraging social engineering and the abuse of the macOS Transparency, Consent, and Control (TCC) feature. The primary attack vector begins with a phishing email that entices users to download an AppleScript file disguised as a genuine Microsoft document, titled "Confirmation_Token_Vesting.docx.scpt". This technique is designed to exploit the victim's trust, prompting them to execute the file. The core of the attack utilizes AppleScript as a loader, effectively bypassing traditional security measures by manipulating the TCC authorizations. By doing so, the threat actor is able to achieve persistent access to the compromised network without the need to exploit any inherent software vulnerabilities. This method highlights the risks associated with social engineering and the potential for unauthorized access through trusted user interfaces.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
JavaScript Darktrace Darktrace Identifies Cobalt Strike Windows Phishing Tara Gould SnappyBee
Indicators of Compromise (5 / 25 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 153219368080efd938df03ebd119cf1dedf341f9 SHA1 of 319d905b83bf9856b84340493c828a0c 2026-02-07
FileHash-SHA1 5e6f0888e6e4ec4145c29a31c46c9c1a33c8a4cf SHA1 of d3539d71a12fe640f3af8d6fb4c680fd 2026-02-07
FileHash-SHA1 7d9ea7c8934d293429103fd0f8f58b370bd1249b SHA1 of b2b617e62353a672626c13cc7ad81b27f23f91282aad7a3a0db471d84852a9ac 2026-02-07
FileHash-SHA1 9218e2c37c339527736cdc9d9aad88de728931a3 SHA1 of 25b9fdef3061c7dfea744830774ca0e289dba7c14be85f0d4695d382763b409b 2026-02-07
FileHash-SHA1 dfe752f103e8e0cdb6ee419a5e753a451488420c SHA1 of 1a38303fb392ccc5a88d236b4f97ed404a89c1617f34b96ed826e7bb7257e296 2026-02-07