Beware of New Compliance Emails Weaponizing Word/PDF Files to Steal Sensitive Data
A phishing campaign specifically targeting macOS users has been identified, utilizing fraudulent compliance emails to distribute advanced malware.
A phishing campaign specifically targeting macOS users has been identified, utilizing fraudulent compliance emails to distribute advanced malware.
Researchers at Chainbase Lab have detected this campaign, which impersonates legitimate audit and compliance notifications to deceive users.
The attack chain employs social engineering techniques and multi-stage fileless payloads aimed at credential theft and establishing persistent remote access on affected systems.
The attack begins with requests for users to confirm their company's legal name, followed by messages that appear to be from financial auditors or token vesting administrators, including malicious attachments.
The attack unfolds in several stages, initially requesting basic company information to build trust before sending a second wave of emails with subject lines like "FY2025 External Audit" or "Token Vesting Confirmation" deadlines.
The emails contain attachments disguised as Word or PDF files but are actually AppleScript files that use double extensions to conceal their true nature.
SlowMist analysts have identified that the malware uses a multi-stage infection process, with the initial AppleScript file downloading and executing additional malicious code.
A phishing campaign specifically targeting macOS users has been identified, utilizing fraudulent compliance emails to distribute advanced malware.
The primary infection vector involves a file named "Confirmation_Token_Vesting.docx.scpt," which appears legitimate but operates as a script.
The first-stage AppleScript displays fake system settings windows to distract users while executing malicious code in the background.
The script collects system information, including CPU architecture and macOS version, then downloads additional payloads from the domain sevrrhst[.]com.
Deception Evasion Through Fake System Prompts
The malware's detection evasion strategy involves displaying convincing system permission dialogs mimicking macOS security alerts.
These fake prompts incorporate Google avatar elements to appear legitimate, tricking users into entering their administrator passwords.
Once a password is provided, the script validates it and immediately exfiltrates the credentials to a remote server using Base64 encoding.
Beyond credential theft , the malware attempts to bypass macOS TCC protections by injecting SQL statements into the privacy database, gaining camera access, screen recording permissions, and keyboard monitoring capabilities.
This persistence mechanism allows the attacker to maintain long-term access and execute commands through a Node.js runtime environment on the compromised machine.
The campaign infrastructure utilizes temporary domains registered in late January 2026, with the command server at sevrrhst[.]com linked to IP 88.119.171.59, hosting over ten similar malicious domains for infrastructure reuse.
Based on reporting by Cyber Security News.
