Crooks push Mac malware through fake OpenAI Codex ads
ID: 3edffe8d-5732-5b3b-a97f-6a19be6b8847
STIX ID: report--3edffe8d-5732-5b3b-a97f-6a19be6b8847
Feed Name: The Register (Security)
Researchers at Cato Networks uncovered a campaign where attackers place sponsored Google ads linking to convincing fake OpenAI Codex (and Claude Code) download pages that instruct macOS users to paste a Terminal command. The command decodes a URL, fetches and executes attacker-controlled shell scripts that stage a multi-step infection: reporting back to a C2, downloading a universal Mach-O payload to /tmp/helper, removing macOS download security metadata to evade warnings, and executing the final binary. The operation resembles the AMOS macOS stealer, uses ClickFix social-engineering to get users to run commands directly, and employs visitor fingerprinting and iframes to hide malicious content from researchers and non-targeted visitors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
