AppleScript Used to Deliver macOS Malware Disguised as Zoom & Teams Updates

Post Reply
Shane1145
Posts: 1804
Joined: Wed Sep 25, 2024 2:31 pm

AppleScript Used to Deliver macOS Malware Disguised as Zoom & Teams Updates

Post by Shane1145 »

Since Apple removed the popular “right-click and open” Gatekeeper override in August 2024, threat actors have shifted their tactics to deliver malware on macOS.

Among emerging techniques, attackers are increasingly leveraging AppleScript (.scpt) files to bypass security controls and distribute credential stealers often disguised as legitimate software updates from popular applications such as Zoom and Microsoft Teams.

Apple’s removal of the Gatekeeper override eliminated one of the most effective infection vectors for macOS malware.

https://gbhackers.com/macos-malware-3/
Post Reply