Activity timeline
T1059.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 10 reports, and 29 of the 29 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1059.002 AppleScript is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix, as a sub-technique of T1059 Command and Scripting Interpreter. Threadlinqs maps 29 of 2623 tracked threats (1.1%) to it; by severity that is 4 critical, 24 high, 1 medium.
Threats that use T1059.002 most often also use T1059.004 Unix Shell (26 threats), T1005 Data from Local System (24 threats), T1071.001 Web Protocols (24 threats), T1555.003 Credentials from Web Browsers (24 threats), T1082 System Information Discovery (22 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
8 tracked threat actors appear in the threats that use T1059.002; the most frequent are APT38 (3), ClickLock Dev (2), Sapphire Sleet (2), Stardust Chollima (2), UNC1069 (2).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1059.002.
Data sources
Telemetry that can reveal T1059.002, per MITRE ATT&CK.
- Command — Command Execution
- Process — OS API Execution, Process Creation
Threat actors using it
Tracked threats
29 tracked threats use T1059.002.
- Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)high
- MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…high
- Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused…high
- Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malwarehigh
- AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Controlhigh
- Over 250 Fake Download Domains Deliver AMOS and MacSync Infostealers via ClickFix with Server-Side Browser…high
- Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and…high
- macOS ClickFix Campaign Using Browser Fingerprinting Gate to Distribute Atomic Stealer (AMOS) and MacSync…high
- Atomic MacOS (AMOS) Stealer Infection via Fake "macOS Toolkit" Terminal Commandmedium
- XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram…high
- BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency…high
- EtherHiding on macOS: Blockchain-Resolved C2 via Polygon Smart Contracthigh
- SHub Stealer "Reaper" — macOS Infostealer Using applescript:// URL-Scheme Delivery, Filegrabber Module, and…high
- ClickLock Stealer: macOS ClickFix Infostealer Uses 210ms Process-Kill Loops and Fake Authentication Dialogs…high
- macOS Infostealer Hijacks Telegram Desktop Sessions via tdata Theft to Bypass 2FA, Harvests Keychain…high
- ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoorhigh
- MacSync Stealer: 'ClaudeFix' Malvertising Campaign Abuses Shared Claude Chat Links to Deploy macOS Infostealerhigh
- PamStealer: Rust-Based macOS Infostealer Masquerades as Maccy Clipboard Manager, Validates Stolen Passwords…high
- Verified X Ad Spreads Mac Infostealer (Atomic Stealer Variant "MacSync"/DigitStealer) via Fake DynamicLake…high
- macOS ClickFix Campaign Silently Mounts Malicious DMGs (hdiutil attach -nobrowse) to Deploy Atomic macOS…high
- Meow Mac Stealer RAT: macOS ClickFix Lures Deploy AppleScript Infostealer with Persistent RAT Capabilitieshigh
- Fake BlueWallet macOS Stealer — AppleScript Dropper Delivers Infostealer with Clipboard Crypto-Address…high
- Ghost CMS Content API SQL Injection CVE-2026-26980 — Large-Scale ClickFix Watering-Hole Campaign…critical
- MacSync macOS Infostealer Delivered via Google Ads + Weaponized Claude.ai Shared Chats Impersonating Apple…high
- ClickFix macOS Trio: Loader/Script/Helper Campaigns Deliver SHub Stealer, AMOS, and Macsync Stealer with…high
- Axios npm Supply Chain Compromise — Malicious axios@1.14.1 and axios@0.30.4 Inject plain-crypto-js@4.2.1 RAT…critical
- Axios npm Supply Chain Compromise (v1.14.1 / v0.30.4) Reaches OpenAI macOS Signing Pipeline, Forces Apple…critical
- Malicious OpenClaw Skills — AMOS macOS Stealer Supply Chain via ClawHub, SkillsMP, and GitHubcritical
- Matryoshka ClickFix macOS Variant — Nested Heredoc Obfuscation, AppleScript Credential Stealer, Trezor Suite…high
Detection coverage
Threadlinqs maintains 72 detection rules mapped to T1059.002 (SPL 17, KQL 26, Sigma 29). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1059 Command and Scripting Interpreter — 1050 tracked threats at the technique level.