macOS Phishing Attack Targets Token Vesting Data, Disguised as Audit Emails

macOS Phishing Attack Targets Token Vesting Data, Disguised as Audit Emails

N
News Editor 01
2026-07-22 13:25:13
SlowMist discloses a sophisticated phishing campaign targeting macOS users. Attackers trick victims into running AppleScript attachments disguised as audit confirmations, stealing token vesting data and bypassing system privacy controls.
macOS phishingtoken vestingAppleScript attackSlowMistcrypto security

A highly targeted phishing campaign is hitting macOS users in the crypto and tech sectors. Security firm SlowMist analyzed the attack after Chainbase Lab flagged suspicious emails disguised as “audit/compliance confirmation.” The goal: steal token vesting data and credentials.

Emails Masquerade as External Audit Requests

Attackers first ask recipients to confirm their company’s legal English name in a social engineering step. Then they send emails with subject lines “FY2025 External Audit” or “Token Vesting Confirmation – deadline.” The attachments, named “Confirmation_Token_Vesting.docx.scpt,” appear as ordinary Word or PDF files but are actually AppleScript executables.

Multi-Stage Fileless Malware in Action

Once opened, the script displays fake macOS update or repair windows to lower victim suspicion. It collects system info (CPU, macOS version, language) and sends it to remote servers like sevrrhst[.]com. The servers then decide which payload to deliver. Subsequent scripts enable password theft, remote command execution, and dynamic payload injection.

Bypassing macOS Privacy Controls

The attack specifically targets macOS's Transparency, Consent, and Control (TCC) safeguards. By modifying system folders and injecting SQL queries into the TCC database, the scripts covertly gain access to documents, downloads, desktop, camera, screen capture, and keyboard tracking. A Node.js backdoor facilitates remote control and dynamic malware execution. When credential prompts appear, attackers verify the password locally before exfiltrating it via Base64-encoded transfers — the pop-up window is indistinguishable from a real system prompt.

Experts advise: even trusted-looking emails can be dangerous. If exposed, disconnect immediately, reset permissions, and run a security scan.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.