Fake OpenAI Codex Installer Tricks Mac Users Into Pasting Malware Into Terminal
ID: b64394b2-fd71-5b51-834e-e4e26f09e739
STIX ID: report--b64394b2-fd71-5b51-834e-e4e26f09e739
Feed Name: Cyber Press
The report details a malicious campaign where attackers place sponsored Google ads and host convincing Google Sites pages that impersonate an OpenAI Codex download portal. macOS victims are socially engineered (ClickFix) to paste a Terminal command that decodes a remote URL, downloads a staged shell loader and then a universal Mach-O payload staged to /tmp/helper; the chain uses obfuscation (Base64 and AES-encrypted gzip), telemetry tagged with event=pasted, and removes extended attributes to reduce macOS warnings; researchers note strong overlap with Atomic macOS Stealer (AMOS) and provide several IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
