Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Beware of New Compliance Emails Weaponizing Word/PDF Files to Steal Sensitive Data

A phishing campaign specifically targeting macOS users has been identified, utilizing fraudulent compliance emails to distribute advanced malware.

A phishing campaign specifically targeting macOS users has been identified, utilizing fraudulent compliance emails to distribute advanced malware.

Researchers at Chainbase Lab have detected this campaign, which impersonates legitimate audit and compliance notifications to deceive users.

The attack chain employs social engineering techniques and multi-stage fileless payloads aimed at credential theft and establishing persistent remote access on affected systems.

The attack begins with requests for users to confirm their company's legal name, followed by messages that appear to be from financial auditors or token vesting administrators, including malicious attachments.

The attack unfolds in several stages, initially requesting basic company information to build trust before sending a second wave of emails with subject lines like "FY2025 External Audit" or "Token Vesting Confirmation" deadlines.

The emails contain attachments disguised as Word or PDF files but are actually AppleScript files that use double extensions to conceal their true nature.

SlowMist analysts have identified that the malware uses a multi-stage infection process, with the initial AppleScript file downloading and executing additional malicious code.

A phishing campaign specifically targeting macOS users has been identified, utilizing fraudulent compliance emails to distribute advanced malware.
Joseph Cain · Thehackingpost

The primary infection vector involves a file named "Confirmation_Token_Vesting.docx.scpt," which appears legitimate but operates as a script.

The first-stage AppleScript displays fake system settings windows to distract users while executing malicious code in the background.

The script collects system information, including CPU architecture and macOS version, then downloads additional payloads from the domain sevrrhst[.]com.

Deception Evasion Through Fake System Prompts

The malware's detection evasion strategy involves displaying convincing system permission dialogs mimicking macOS security alerts.

These fake prompts incorporate Google avatar elements to appear legitimate, tricking users into entering their administrator passwords.

Advertisement

Once a password is provided, the script validates it and immediately exfiltrates the credentials to a remote server using Base64 encoding.

Beyond credential theft , the malware attempts to bypass macOS TCC protections by injecting SQL statements into the privacy database, gaining camera access, screen recording permissions, and keyboard monitoring capabilities.

This persistence mechanism allows the attacker to maintain long-term access and execute commands through a Node.js runtime environment on the compromised machine.

The campaign infrastructure utilizes temporary domains registered in late January 2026, with the command server at sevrrhst[.]com linked to IP 88.119.171.59, hosting over ten similar malicious domains for infrastructure reuse.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories