Hackers Place Fake Codex Download Above Legitimate OpenAI Result to Infect Mac Users
ID: 565cb8cc-016a-50fd-9931-9d0c2641a610
STIX ID: report--565cb8cc-016a-50fd-9931-9d0c2641a610
Feed Name: GBHackers
Threat actors bought sponsored Google Search ads that point to a Google Sites lure impersonating an OpenAI Codex download; macOS users are instructed to paste a Terminal command that decodes and pipes remote content to zsh, launching a three-stage loader that removes quarantine attributes and executes a universal Mach-O payload. Cato Networks links the campaign to AMOS-like delivery patterns (base64 curl loaders, xattr -c, /tmp/helper staging and telemetry at api/metrics/run?event=pasted) and identifies iframe and payload hosts (e.g., bright-links.com, trekmesh15.com, grove-12.com); defenders are advised to restrict risky CLI execution, monitor for curl | zsh and xattr -c behavior, and block known malicious iframe infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
