Splunk Enterprise Security released an anomaly analytic to identify suspicious macOS osascript executions that invoke AppleScript display alert or display dialog commands using credential- or security-themed wording. Such dialogs can impersonate macOS authentication or security notices and trick users into disclosing passwords and other sensitive data, a technique tracked as MITRE ATT&CK T1056.002 (GUI Input Capture).
The detection uses osquery process telemetry, maps the execution mechanism to T1059.002 (AppleScript), and generates intermediate risk events rather than notable findings; it is disabled by default. osascript is a legitimate native macOS utility but can also execute AppleScript or JavaScript for Automation to collect clipboard or system data, manipulate applications, and present fake authentication prompts, so alerts require investigation to distinguish malicious activity from legitimate MDM, deployment, support, and automation scripts.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Splunk updated its "MacOS Osascript Displaying Suspicious User Prompt" analytic, which detects osascript commands using AppleScript dialogs or alerts containing credential- and security-themed language. The disabled-by-default analytic creates intermediate risk events from osquery process telemetry and is mapped to ATT&CK AppleScript and GUI Input Capture.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceloobins.io
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.