• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    macOS ClickFix: base64-piped bash execution via Terminal

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 10 days ago•1•0•1

    Detects the execution of bash commands containing base64 decoding instructions, often used by adversaries to decode and execute obfuscated scripts or payloads. The rule specifically looks for command lines invoking base64 along with keywords like 'echo' or 'reCAPTCHA', which are commonly associated with malicious droppers or phishing-related scripts.

    Cortex XDR

    Tags

    T1059 - Command and Scripting InterpreterT1059.004 - Unix ShellT1027.010 - Command ObfuscationTA0002 - ExecutionTA0005 - StealthProcess CreationCommand ExecutionLinuxmacOSLinux Auditd

    Found in

    • Macfinger ClickFix Campaign Distributing AMOS StealerLast updated 10 days ago
    • Macfinger ClickFix Campaign Distributing AMOS StealerLast updated 10 days ago
    • Macfinger ClickFix Campaign Distributing AMOS StealerLast updated 10 days ago
    • Macfinger ClickFix Campaign Distributing AMOS StealerLast updated 10 days ago
    • Macfinger ClickFix Campaign Distributing AMOS StealerLast updated 10 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?