logo

New ClickFix Campaign Targets macOS Users With Fake Disk Cleanup Tools

ID: def0362f-0d2c-56ba-9ae0-8b93797355eb

STIX ID: report--def0362f-0d2c-56ba-9ae0-8b93797355eb

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Varshini

...
...

Cybersecurity researchers uncovered the ClickFix campaign targeting macOS users via fake disk-cleanup and troubleshooting guides hosted on user-content platforms (Medium, Squarespace, Craft). Victims are social-engineered to paste obfuscated Terminal commands that download infostealers (Macsync, Shub Stealer, AMOS), replace legitimate crypto wallet apps with trojanized versions, stage stolen data in temporary folders, and maintain persistence via fake update or helper plist files; the campaign uses evasion techniques (no-disk initial execution, sandbox checks, a Russian-layout kill switch) and a Telegram-bot fallback for command-and-control discovery. Indicators include several domains used to host the fraudulent instructions and Microsoft has updated XProtect and introduced a macOS prompt to warn users about pasting commands.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.