logo

New “ClickFix” Campaign Bypasses Gatekeeper to Hijack macOS Devices

ID: 4fe6f4dc-cc3e-5713-85c0-94d2fe314da3

STIX ID: report--4fe6f4dc-cc3e-5713-85c0-94d2fe314da3

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-05-09

Date Updated: 2026-05-22

Author: Ddos

...
...

Microsoft researchers warn of an active macOS infostealer campaign using social‑engineering 'ClickFix' posts that trick users into pasting Terminal commands; three tracked variants (Loader Install, Script Install, Helper/AMOS) employ in‑memory execution, C2 via Telegram fallback, virtualization checks, trojanized crypto wallets, and a root‑persistent Launch Daemon to steal credentials, iCloud data, and crypto funds—highlighting that copying arbitrary Terminal commands from untrusted sources can bypass Gatekeeper and enable malware execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.