Apple @ Work: New ClickFix malware for macOS brings a potential new backdoor to your enterprise fleet


Apple @ Work is an exclusive presentation from MosyleApple’s only unified platform. Mosyle is the only solution that integrates into a single professional-grade platform all the solutions necessary to seamlessly and automatically deploy, manage and protect Apple devices at work. More than 45,000 organizations trust Mosyle to keep millions of Apple devices up and running effortlessly and at an affordable cost. Request your EXTENDED TEST today and understand why Mosyle is everything you need to work with Apple.

While macOS is inherently secure by design, hackers and scammers are increasingly relying on social engineering to bypass native protections. A new report published by Netskope Threat Labs details a new and highly sophisticated macOS ClickFix campaign. This attack tricks people into deploying an AppleScript-based information stealer and persistent remote access Trojan.

About Apple@Work: Bradley Chambers has been an Apple IT administrator since 2009. Through his experience deploying and managing firewalls, switches, a mobile device management system, enterprise-grade WiFi, thousands of Macs, and thousands of iPads, Bradley will highlight the ways Apple IT administrators deploy Apple devices, build networks to support them, train users, share stories from the trenches of IT management, and ways Apple could improve its products for IT departments.

An infection chain without files

The new macOS ClickFix campaign is based on a classic social engineering framework. Users are directed to websites compromised or controlled by attackers that imitate legitimate services (which is why services like brand shield are becoming essential). Netskope found fake macOS optimization utility pages, fake GitHub repositories, and even localized IT support pages. These sites direct end users to manually copy and paste a specific command into the macOS Terminal.

When the victim clicks the copy button on the fake website, malicious JavaScript silently drops the execution string to their clipboard. Running this command in Terminal results in a script that runs entirely in memory. This fileless approach leaves no crumbs on the local drive, allowing the initial loader to easily evade standard malware scans.

Once the secondary payload runs, it displays a fake Mac System Preferences dialog that asks the end user for their macOS login password to update settings. If the user enters the password, the malware uses it to unlock the macOS keychain and begins extracting saved passwords, session cookies, and data from messaging apps.

On top of that, the even worse behavior is the way it handles desktop crypto wallets. The malware targets 25 different desktop wallets. It actively removes the running legitimate application, overwrites the main application package with a trojanized version, and forces an ad hoc code signing. This restores a structurally valid signature, allowing the newly modified application to start without triggering macOS Gatekeeper warnings. If you have substantial holdings of any crypto, do not use single signature wallets for reasons like this.

To establish long-term access, the payload installs a background configuration file disguised as an Apple system account process called com.apple.accountsd. This process polls the command and control server every minute. This allows the attacker to maintain a constant beacon loop and remotely execute arbitrary code on the infected Mac at any time.

9to5Mac’s opinion

This campaign is a perfect example of how far a purely script-based macOS payload can go. Attackers do not use zero-day vulnerabilities or complex kernel exploits. They are simply using the native macOS toolchain against the user.

For IT departments, this highlights the critical need for ongoing security training. Users should be taught to never paste unknown commands into the Terminal, no matter how legitimate the website appears. One could argue that blocking access to Terminal on enterprise Macs may become the default option for many features.

Apple @ Work is an exclusive presentation from MosyleApple’s only unified platform. Mosyle is the only solution that integrates into a single professional-grade platform all the solutions necessary to seamlessly and automatically deploy, manage and protect Apple devices at work. More than 45,000 organizations trust Mosyle to keep millions of Apple devices up and running effortlessly and at an affordable cost. Request your EXTENDED TEST today and understand why Mosyle is everything you need to work with Apple.

FTC: We use automatic affiliate links that generate income. Further.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *