# T1059.002 AppleScript

> As of 2026-10-05, T1059.002 (AppleScript) appears in 29 tracked threats, first reported 2026-02-16 and most recently 2026-10-02, with linked actors including APT38, ClickLock Dev, Sapphire Sleet; it most often appears alongside T1059.004 (Unix Shell).

- **Tracked threats:** 29 (4 critical, 24 high, 1 medium)
- **First seen:** 2026-02-16
- **Last seen:** 2026-10-02
- **Threat actors:** 8
- **Detection rules:** 72 (counts only; Blue tier and above)

## Key facts

- **ID:** T1059.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution
- **Matrix:** Enterprise
- **Parent:** T1059
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1059/002/

## Activity timeline

T1059.002 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-10-02. The busiest month was 2026-07 with 10 reports, and 29 of the 29 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1059.002 AppleScript is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix, as a sub-technique of [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059). Threadlinqs maps 29 of 2623 tracked threats (1.1%) to it; by severity that is 4 critical, 24 high, 1 medium.

Threats that use T1059.002 most often also use [T1059.004 Unix Shell](https://intel.threadlinqs.com/technique/T1059.004) (26 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (24 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (24 threats), [T1555.003 Credentials from Web Browsers](https://intel.threadlinqs.com/technique/T1555.003) (24 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (22 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

8 tracked threat actors appear in the threats that use T1059.002; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (3), [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) (2), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (2), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (2), [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) (2).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1059.002.

- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)
- [M1045 Code Signing](https://attack.mitre.org/mitigations/M1045/)

## Data sources

Telemetry that can reveal T1059.002, per MITRE ATT&CK.

- Command — Command Execution
- Process — OS API Execution, Process Creation

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 3
- [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) — 2
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 2
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 2
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 2
- [AMOS Operators](https://intel.threadlinqs.com/actor/AMOS%20Operators) — 1
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 1

## Tracked threats

29 tracked threats use T1059.002.

- [Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)](https://intel.threadlinqs.com/threat/TL-2026-2916) — high — 2026-10-02
- [MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…](https://intel.threadlinqs.com/threat/TL-2026-2637) — high — 2026-09-24
- [Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused…](https://intel.threadlinqs.com/threat/TL-2026-2604) — high — 2026-09-21
- [Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malware](https://intel.threadlinqs.com/threat/TL-2026-2197) — high — 2026-08-29
- [AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Control](https://intel.threadlinqs.com/threat/TL-2026-2029) — high — 2026-08-16
- [Over 250 Fake Download Domains Deliver AMOS and MacSync Infostealers via ClickFix with Server-Side Browser…](https://intel.threadlinqs.com/threat/TL-2026-1907) — high — 2026-08-06
- [Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and…](https://intel.threadlinqs.com/threat/TL-2026-1899) — high — 2026-08-05
- [macOS ClickFix Campaign Using Browser Fingerprinting Gate to Distribute Atomic Stealer (AMOS) and MacSync…](https://intel.threadlinqs.com/threat/TL-2026-1894) — high — 2026-08-05
- [Atomic MacOS (AMOS) Stealer Infection via Fake "macOS Toolkit" Terminal Command](https://intel.threadlinqs.com/threat/TL-2026-1813) — medium — 2026-08-02
- [XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram…](https://intel.threadlinqs.com/threat/TL-2026-1792) — high — 2026-07-31
- [BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency…](https://intel.threadlinqs.com/threat/TL-2026-1719) — high — 2026-07-27
- [EtherHiding on macOS: Blockchain-Resolved C2 via Polygon Smart Contract](https://intel.threadlinqs.com/threat/TL-2026-1670) — high — 2026-07-24
- [SHub Stealer "Reaper" — macOS Infostealer Using applescript:// URL-Scheme Delivery, Filegrabber Module, and…](https://intel.threadlinqs.com/threat/TL-2026-1475) — high — 2026-07-18
- [ClickLock Stealer: macOS ClickFix Infostealer Uses 210ms Process-Kill Loops and Fake Authentication Dialogs…](https://intel.threadlinqs.com/threat/TL-2026-1440) — high — 2026-07-17
- [macOS Infostealer Hijacks Telegram Desktop Sessions via tdata Theft to Bypass 2FA, Harvests Keychain…](https://intel.threadlinqs.com/threat/TL-2026-1424) — high — 2026-07-16
- [ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1402) — high — 2026-07-16
- [MacSync Stealer: 'ClaudeFix' Malvertising Campaign Abuses Shared Claude Chat Links to Deploy macOS Infostealer](https://intel.threadlinqs.com/threat/TL-2026-1384) — high — 2026-07-15
- [PamStealer: Rust-Based macOS Infostealer Masquerades as Maccy Clipboard Manager, Validates Stolen Passwords…](https://intel.threadlinqs.com/threat/TL-2026-1104) — high — 2026-07-05
- [Verified X Ad Spreads Mac Infostealer (Atomic Stealer Variant "MacSync"/DigitStealer) via Fake DynamicLake…](https://intel.threadlinqs.com/threat/TL-2026-1095) — high — 2026-07-03
- [macOS ClickFix Campaign Silently Mounts Malicious DMGs (hdiutil attach -nobrowse) to Deploy Atomic macOS…](https://intel.threadlinqs.com/threat/TL-2026-0923) — high — 2026-06-23
- [Meow Mac Stealer RAT: macOS ClickFix Lures Deploy AppleScript Infostealer with Persistent RAT Capabilities](https://intel.threadlinqs.com/threat/TL-2026-0842) — high — 2026-06-17
- [Fake BlueWallet macOS Stealer — AppleScript Dropper Delivers Infostealer with Clipboard Crypto-Address…](https://intel.threadlinqs.com/threat/TL-2026-0648) — high — 2026-06-01
- [Ghost CMS Content API SQL Injection CVE-2026-26980 — Large-Scale ClickFix Watering-Hole Campaign…](https://intel.threadlinqs.com/threat/TL-2026-0575) — critical — 2026-05-24
- [MacSync macOS Infostealer Delivered via Google Ads + Weaponized Claude.ai Shared Chats Impersonating Apple…](https://intel.threadlinqs.com/threat/TL-2026-0491) — high — 2026-05-10
- [ClickFix macOS Trio: Loader/Script/Helper Campaigns Deliver SHub Stealer, AMOS, and Macsync Stealer with…](https://intel.threadlinqs.com/threat/TL-2026-0471) — high — 2026-05-06
- [Axios npm Supply Chain Compromise — Malicious axios@1.14.1 and axios@0.30.4 Inject plain-crypto-js@4.2.1 RAT…](https://intel.threadlinqs.com/threat/TL-2026-0397) — critical — 2026-04-20
- [Axios npm Supply Chain Compromise (v1.14.1 / v0.30.4) Reaches OpenAI macOS Signing Pipeline, Forces Apple…](https://intel.threadlinqs.com/threat/TL-2026-0351) — critical — 2026-04-11
- [Malicious OpenClaw Skills — AMOS macOS Stealer Supply Chain via ClawHub, SkillsMP, and GitHub](https://intel.threadlinqs.com/threat/TL-2026-0136) — critical — 2026-02-24
- [Matryoshka ClickFix macOS Variant — Nested Heredoc Obfuscation, AppleScript Credential Stealer, Trezor Suite…](https://intel.threadlinqs.com/threat/TL-2026-0120) — high — 2026-02-16

## Related CVEs

CVEs referenced by the tracked threats that use T1059.002, most frequent first.

- [CVE-2026-26980](https://intel.threadlinqs.com/cve/CVE-2026-26980)

## Detection coverage

Threadlinqs maintains 72 detection rules mapped to T1059.002 (SPL 17, KQL 26, Sigma 29). Rule content is available to Blue tier accounts and above; this page shows counts only.

72 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) — 1050 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1059.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
