← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
ClickFix Malware Uses macOS Script Editor to Deliver Atomic Stealer
Over the years, Jamf Threat Labs developed a broad library of indicators for statically detecting malware, alongside behavioral detections that flag suspicious actions at runtime. This two-pronged approach has proven highly effective at catching infostealers in the wild. Through one of these behavioral detections, we identified a ClickFix-style attack — one that stood out immediately because it ditched the typical Terminal-based execution entry point entirely. Instead, this malware leveraged macOS Script Editor as the execution vector while maintaining a familiar final payload. Script Editor has a well-documented history as a malware delivery mechanism, so its presence here isn't surprising. What is notable is its role in this ClickFix campaign and the fact that it was invoked via a URL scheme.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
AtomicStealer
ClickFix
Indicators of Compromise (5)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 04566d1d3f9717b2e7e6b643775d9ca72cef942f6df9ce075cf8c73a1bd2565a | — | 2026-04-08 | |
| FileHash-SHA256 | 3d3c91ee762668c85b74859e4d09a2adfd34841694493b82659fda77fe0c2c44 | — | 2026-04-08 | |
| URL | https://dryvecar.com/cleaner3/update | — | 2026-04-08 | |
| URL | https://dryvecar.com/curl/04566d1d3f9717b2e7e6b643775d9ca72cef942f6df9ce075cf8c73a1bd2565a | — | 2026-04-08 | |
| domain | dryvecar.com | — | 2026-04-08 |