Meow AppleScript RAT Targeting macOS via ClickFix
Score: 8/10

Meow AppleScript RAT Targeting macOS via ClickFix

A Russian-speaking attacker is deploying the Meow AppleScript RAT via ClickFix social engineering lures to exfiltrate data and hijack cryptocurrency wallets on macOS.

Executive Summary

In May 2026, a new campaign attributed to a Russian-speaking operator was identified deploying an upgraded variant of the 'Meow' malware. Unlike previous versions, this variant functions as a persistent Remote Access Trojan (RAT) that uses fileless execution to evade detection. The campaign targets users in Asia, North America, and Oceania, specifically within the technology, media, and business services sectors.

The attack utilizes the 'ClickFix' technique, where victims are socially engineered into executing a curl command from their terminal. The malware performs CIS-geofencing to avoid Russian targets, harvests browser and system credentials via fake dialogs, and employs a sophisticated routine to overwrite legitimate cryptocurrency wallet applications with trojanized versions. The inclusion of a persistent C2 beaconing loop allows the operator to maintain long-term access and execute arbitrary code on infected hosts.

Key Details

Threat Name

Meow AppleScript RAT

Affects

—

Adversary

—

Malware/Tools

Meow

Report Score

8out of 10
Quality Score
Good
IOC Quality8
TTP Details9
Detection Guidance7
Enterprise Relevance8
Clarity & Structure9
Technical Depth9

Sources