Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Fake Compliance Emails Weaponize Word and PDF Attachments to Steal Sensitive Data

A newly identified phishing campaign is targeting macOS users by exploiting fake "audit/compliance confirmation" emails to steal sensitive data.

A newly identified phishing campaign is targeting macOS users by exploiting fake "audit/compliance confirmation" emails to steal sensitive data.

The campaign employs business-themed lures and malicious attachments disguised as Word or PDF files to trick recipients into executing an AppleScript-based payload. Initially, emails request confirmation of the company's legal English name and are followed by subjects like "FY2025 External Audit" or "Token Vesting Confirmation submission deadline."

Chainbase Lab first detected these suspicious messages, posing as routine corporate compliance checks, and collaborated with the SlowMist security team for analysis. The emails include files such as "Confirmation_Token_Vesting.docx.scpt," which appear as standard DOCX documents but are actually AppleScript (.scpt) files concealed behind a double extension.

Upon execution, the script initiates a multi-stage, largely fileless infection chain specifically designed for macOS. The initial AppleScript stage creates the illusion of a legitimate system update by opening macOS System Settings, gathering system details, and sending profiling data to a remote server to deliver an appropriate payload.

Further stages involve downloading additional malicious code from sevrrhst[.]com, executing fake progress bars, and displaying realistic macOS-style permission prompts. The script validates user passwords, exfiltrates credentials, and attempts to bypass macOS's Transparency, Consent, and Control (TCC) protections by tampering with the TCC privacy database.

A newly identified phishing campaign is targeting macOS users by exploiting fake "audit/compliance confirmation" emails to steal sensitive data.
Heather Lyons · Thehackingpost

The malware grants itself broad permissions, accesses sensitive controls, establishes persistence, and communicates with its command-and-control (C2) infrastructure. It prepares a Node.js runtime, runs a core script, and sends system inventory information back to the C2 server. The infrastructure shows fast-flux behavior and shares domains with ongoing operations.

Organizations are advised to train staff to be cautious of unexpected emails requesting document review or password entry, especially those involving double extensions or unusual prompts. Suspected victims should disconnect affected systems, reset the TCC database, terminate suspicious processes, and conduct a full incident response investigation.

Filename SHA256 URL C2 / Domain IP Address

Confirmation_Token_Vesting.docx.scpt 3e4d35903c51db3da8d4bd77491b5c181b7361aaf152609d03a1e2bb86faee43 https://sevrrhst[.]com/css/controller.php sevrrhst[.]com 88.119.171.59

Advertisement

env_arm.zip f9e0376114c57d659025ceb46f1ef48aa80b8af5909b2de0cf80e88040fef345 https://sevrrhst[.]com/inc/register.php sevrrhst[.]com 88.119.171.59

index.js 0f1e457488fe799dee7ace7e1bc2df4c1793245f334a4298035652ebeb249414 — sevrrhst[.]com 88.119.171.59

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories