logo

From Windows to macOS: ClickFix attacks shift tactics with ChatGPT-based lures

ID: b447375f-58d1-5545-8d41-ed57d655cfb2

STIX ID: report--b447375f-58d1-5545-8d41-ed57d655cfb2

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-03-17

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Sophos and other researchers observed ClickFix campaigns shifting to macOS, using ChatGPT-shared conversations and GitHub-themed landing pages to trick users into running obfuscated Terminal/AppleScript commands that install MacSync/AMOS infostealers. Over time the operation evolved into a modular, stealthy, multi-stage loader service with API-protected C2, in-memory payloads, telemetry/tracking, and advanced data-harvesting—targeting browser credentials, SSH keys, cloud configs, and cryptocurrency wallets (including Ledger tampering).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.