logo

MacOS ClickFix AMOS Campaign

ID: b37cb390-5fc6-51d4-829e-6ec686f4788e

STIX ID: report--b37cb390-5fc6-51d4-829e-6ec686f4788e

Feed Name: Ransomware ISAC Blog

Threat Score
78/100

Date Published: 2026-09-17

Date Updated: 2026-09-17

Author: [email protected] (Dani [Varys] Z & Dimple [LocalHost] Gajra)

...
...

Since July 28, 2026 Ransom-ISAC tracked the ClickFix campaign that injects a t.js loader into compromised (mostly WordPress) sites to display a fake reCAPTCHA "Bot Protection" overlay which instructs macOS users to paste a Terminal command; that command fetches and runs a stager that deploys Atomic macOS Stealer (AMOS) to harvest browser credentials, Keychain items, and cryptocurrency wallets. Over seven weeks the tracker observed over 1,650 distinct infected websites, rapidly rotating C2 infrastructure (154 observed hostnames), payload hashes and network IOCs; the report provides regex and YARA detection patterns, host- and endpoint-level indicators, MITRE ATT&CK mapping, and remediation advice for site owners, hosts, and Mac users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.