Suspicious Curl Output Piped To Bash On macOS via ClickFix

PremiumReviewedSigma · Medium · v1
Product
macos
Category
process_creation
Author
HuntRule
Published
2026-05-20
Updated
2026-08-28

ATT&CK techniques

Execution → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule detects a curl download whose output is piped directly into a bash shell on macOS, matching the ClickFix social-engineering chain that tricks users into pasting a terminal command. This technique is used to deliver the Odyssey and ACR infostealers after a fake Cloudflare human-verification prompt. Fetching and executing remote code in one step lets the operator run a payload with no file written to disk beforehand.

Related detections9 linkedT1059.004 — drag to rearrange
Malicious Remote Script Piped Directly to a Shell (via process_creation)
HamsaUpdate Linux Payload Download via Wget Piped to Bash (via process_creation)
Malicious Curl to Shell Dropper from Paste Site via Command Line
Malicious kagent RAT Delivery via HuggingFace Space Download (via process_creation)
Suspicious Remote Script Execution via curl Piped to bash with nohup on macOS (via process_creation)
Suspicious Botnet Payload Drop to Hidden Xdiag Temp Path
Malicious Remote Payload Piped to Shell via wget on PAN-OS
Suspicious Remote Script Downloaded via curl and Piped to Shell (via process_creation)
Suspicious File Download to tmp and Quarantine Removal via curl and xattr
Suspicious Curl Output Piped To Bash On macOS via ClickFix
Pivot detection · T1059.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.