PULSE NAME
ClickFix Malware Uses macOS Script Editor to Deliver Atomic Stealer
WHITE dylanroth7 2026-04-08 Modified: 2026-04-08
5
IOCs
LOW VOLUME
Over the years, Jamf Threat Labs developed a broad library of indicators for statically detecting malware, alongside behavioral detections that flag suspicious actions at runtime. This two-pronged approach has proven highly effective at catching infostealers in the wild. Through one of these behavioral detections, we identified a ClickFix-style attack — one that stood out immediately because it ditched the typical Terminal-based execution entry point entirely. Instead, this malware leveraged macOS Script Editor as the execution vector while maintaining a familiar final payload. Script Editor has a well-documented history as a malware delivery mechanism, so its presence here isn't surprising. What is notable is its role in this ClickFix campaign and the fact that it was invoked via a URL scheme.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
AtomicStealer ClickFix
Indicators of Compromise (5)
All FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 04566d1d3f9717b2e7e6b643775d9ca72cef942f6df9ce075cf8c73a1bd2565a 2026-04-08
FileHash-SHA256 3d3c91ee762668c85b74859e4d09a2adfd34841694493b82659fda77fe0c2c44 2026-04-08
URL https://dryvecar.com/cleaner3/update 2026-04-08
URL https://dryvecar.com/curl/04566d1d3f9717b2e7e6b643775d9ca72cef942f6df9ce075cf8c73a1bd2565a 2026-04-08
domain dryvecar.com 2026-04-08