logo

New ClickFix Attack Targets macOS Users With Fake Disk Cleanup and Utility Lures

ID: 4a22ac4b-dcd2-503f-b687-cf9082654531

STIX ID: report--4a22ac4b-dcd2-503f-b687-cf9082654531

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Tushar Subhra Dutta

...
...

This report details the 'ClickFix' macOS campaign where attackers publish fake disk-cleanup/system utility guides that instruct users to paste Terminal commands which then download and execute infostealer payloads (Macsync, Shub Stealer, AMOS). The malware harvests passwords, Keychain data, browser credentials, iCloud and cryptocurrency wallet material, establishes persistence via LaunchAgents/LaunchDaemons (including masquerading as Google Update), and uses a variety of C2/endpoints; the report includes numerous domains, IPs, URLs, SHA-256 hashes, file paths, and detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.