New ClickFix Campaign Targets macOS Users With Fake Disk Cleanup Tools
ID: def0362f-0d2c-56ba-9ae0-8b93797355eb
STIX ID: report--def0362f-0d2c-56ba-9ae0-8b93797355eb
Feed Name: Cyber Press
Cybersecurity researchers uncovered the ClickFix campaign targeting macOS users via fake disk-cleanup and troubleshooting guides hosted on user-content platforms (Medium, Squarespace, Craft). Victims are social-engineered to paste obfuscated Terminal commands that download infostealers (Macsync, Shub Stealer, AMOS), replace legitimate crypto wallet apps with trojanized versions, stage stolen data in temporary folders, and maintain persistence via fake update or helper plist files; the campaign uses evasion techniques (no-disk initial execution, sandbox checks, a Russian-layout kill switch) and a Telegram-bot fallback for command-and-control discovery. Indicators include several domains used to host the fraudulent instructions and Microsoft has updated XProtect and introduced a macOS prompt to warn users about pasting commands.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
