// ThreatHuntingLabs  ·  writeup

MacSync: From ClickFix to Data Theft — Flash Hunt

ThreatHuntingLabs EDR TelemetryESF (Endpoint Security Framework)KQL

Case Context

A Flash Hunt on Threat Hunting Labs — the platform’s rapid, single-session investigation format, distinct from the guided multi-hour cases. Per the platform’s own public listing: a macOS drill focused on Base64 pipe-to-shell execution, AppleScript shell orchestration, credential and developer-artifact staging, HTTP archive upload, cleanup verification, and behavior-first detection design.

Threat Hunting Labs has a strict no-public-writeup policy on active labs to protect scoring and leaderboards for other users, so this page is intentionally an overview: what I did and what I found, not the queries or the specific answers that got me there.

A macOS workstation alert traced a ClickFix-style lure (a fake installer page with a copy-to-Terminal prompt) through to a Base64-encoded shell execution chain, AppleScript (osascript) orchestrating dozens of shell children, credential and developer-secret staging (keychain, cloud, and SSH material), an archived HTTP upload, and post-exfiltration cleanup — all within roughly a minute, with no persistence established anywhere.

Techniques Encountered

Thirteen MITRE ATT&CK techniques surfaced during the hunt, spanning phishing-style delivery, macOS-native scripting, credential access, and web-based exfiltration:

MITRE ATT&CK techniques encountered during the hunt

Prioritising Findings — Pyramid of Pain

Six findings came out of the hunt, weighted by how costly each is for the attacker to change:

Pyramid of Pain breakdown of findings from the hunt

What I Practiced

Credential

Earned a Distinction (100%, zero incorrect attempts) on this Flash Hunt.

Flash Hunt Distinction badge

Verify: https://www.threathuntinglabs.com/badges/da8c36c5-41c7-4332-bcaa-5358935fabff