logo

Crooks push Mac malware through fake OpenAI Codex ads

ID: 3edffe8d-5732-5b3b-a97f-6a19be6b8847

STIX ID: report--3edffe8d-5732-5b3b-a97f-6a19be6b8847

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

...
...

Researchers at Cato Networks uncovered a campaign where attackers place sponsored Google ads linking to convincing fake OpenAI Codex (and Claude Code) download pages that instruct macOS users to paste a Terminal command. The command decodes a URL, fetches and executes attacker-controlled shell scripts that stage a multi-step infection: reporting back to a C2, downloading a universal Mach-O payload to /tmp/helper, removing macOS download security metadata to evade warnings, and executing the final binary. The operation resembles the AMOS macOS stealer, uses ClickFix social-engineering to get users to run commands directly, and employs visitor fingerprinting and iframes to hide malicious content from researchers and non-targeted visitors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.