假冒 Homebrew 页面通过 ClickFix 传播 Cuckoo Stealer | macOS 威胁狩猎分析
hunt.io | 研究 | #supply-chain | #malware | #threat-hunting | #macos | #typosquatting | #homebrew | #cuckoo-stealer | #clickfix | #info-stealer
摘要
假冒 Homebrew 仿冒域名经 ClickFix 传播 Cuckoo Stealer:一阶段脚本以 dscl authonly 反复校验窃取真实凭据,二阶段为具备 LaunchAgent 持久化的 macOS 窃密/RAT,目标覆盖 20+ 加密货币钱包应用。
- 发布时间
- 收录时间
Skip to content