Fake Compliance Emails Weaponize Word and PDF Attachments to Steal Sensitive Data
A newly identified phishing campaign is targeting macOS users by exploiting fake "audit/compliance confirmation" emails to steal sensitive data.
A newly identified phishing campaign is targeting macOS users by exploiting fake "audit/compliance confirmation" emails to steal sensitive data.
The campaign employs business-themed lures and malicious attachments disguised as Word or PDF files to trick recipients into executing an AppleScript-based payload. Initially, emails request confirmation of the company's legal English name and are followed by subjects like "FY2025 External Audit" or "Token Vesting Confirmation submission deadline."
Chainbase Lab first detected these suspicious messages, posing as routine corporate compliance checks, and collaborated with the SlowMist security team for analysis. The emails include files such as "Confirmation_Token_Vesting.docx.scpt," which appear as standard DOCX documents but are actually AppleScript (.scpt) files concealed behind a double extension.
Upon execution, the script initiates a multi-stage, largely fileless infection chain specifically designed for macOS. The initial AppleScript stage creates the illusion of a legitimate system update by opening macOS System Settings, gathering system details, and sending profiling data to a remote server to deliver an appropriate payload.
Further stages involve downloading additional malicious code from sevrrhst[.]com, executing fake progress bars, and displaying realistic macOS-style permission prompts. The script validates user passwords, exfiltrates credentials, and attempts to bypass macOS's Transparency, Consent, and Control (TCC) protections by tampering with the TCC privacy database.
A newly identified phishing campaign is targeting macOS users by exploiting fake "audit/compliance confirmation" emails to steal sensitive data.
The malware grants itself broad permissions, accesses sensitive controls, establishes persistence, and communicates with its command-and-control (C2) infrastructure. It prepares a Node.js runtime, runs a core script, and sends system inventory information back to the C2 server. The infrastructure shows fast-flux behavior and shares domains with ongoing operations.
Organizations are advised to train staff to be cautious of unexpected emails requesting document review or password entry, especially those involving double extensions or unusual prompts. Suspected victims should disconnect affected systems, reset the TCC database, terminate suspicious processes, and conduct a full incident response investigation.
Filename SHA256 URL C2 / Domain IP Address
Confirmation_Token_Vesting.docx.scpt 3e4d35903c51db3da8d4bd77491b5c181b7361aaf152609d03a1e2bb86faee43 https://sevrrhst[.]com/css/controller.php sevrrhst[.]com 88.119.171.59
env_arm.zip f9e0376114c57d659025ceb46f1ef48aa80b8af5909b2de0cf80e88040fef345 https://sevrrhst[.]com/inc/register.php sevrrhst[.]com 88.119.171.59
index.js 0f1e457488fe799dee7ace7e1bc2df4c1793245f334a4298035652ebeb249414 — sevrrhst[.]com 88.119.171.59
Based on reporting by GBHackers.
