Security researchers have identified a new threat vector targeting macOS systems, where stealer malware is being distributed using AppleScript (.scpt) files. This technique allows attackers to bypass traditional detection mechanisms by leveraging the scripting capabilities native to macOS, increasing the stealth and effectiveness of malware campaigns against Apple users. The emergence of this vector highlights the evolving tactics of threat actors seeking to compromise macOS environments, which have historically been perceived as more secure than other platforms.
In response to the growing sophistication and prevalence of macOS-targeted malware, security experts are developing new tools and datasets to improve detection and defense. Notably, researchers are preparing to release Malet, the largest public dataset of macOS malware, and Katalina, an open-source static analysis tool designed to process large volumes of binaries efficiently. These initiatives aim to address the gap in macOS malware research and provide defenders with better resources to identify and mitigate threats, including those exploiting AppleScript-based attack vectors.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
A separate report highlighted the release or promotion of new defensive security tools designed to detect and respond to increasing macOS malware and threat activity. The tools were positioned as a response to the expanding macOS threat landscape.
Security reporting described the emergence of compiled AppleScript (.scpt) files as a new delivery and evasion technique for macOS stealer malware. The coverage framed this as part of a broader rise in macOS-focused threats.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.