ClickFix 2026: New AppleScript Malware Held macOS Users Hostage for Passwords
ID: 260590a3-d3ba-53c5-924f-411b4d6bbe6e
STIX ID: report--260590a3-d3ba-53c5-924f-411b4d6bbe6e
Feed Name: securityonline.info
Netskope Threat Labs reports on the ClickFix campaign: a cross-platform social-engineering attack that lures desktop users into pasting malicious commands (presented as CAPTCHAs or browser updates) to install an infostealer. On macOS the malware displays a convincing, non-closable AppleScript dialog to harvest the plaintext login password, enabling Keychain decryption, cookie and credential theft (including browser extensions and crypto wallets) and potential MFA bypass; users are warned not to paste commands from websites and to rely on OS protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
