logo

ClickFix Style Attack Uses Grok, ChatGPT for Malware Delivery

ID: 1ab3ae93-9b5a-5dbb-af1b-721ece76dd02

STIX ID: report--1ab3ae93-9b5a-5dbb-af1b-721ece76dd02

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2025-12-10

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Huntress researchers describe a ClickFix-style campaign in which attackers poison search results and publish shared AI-chat conversations that instruct victims to run terminal commands; executing those commands installs AMOS, a persistent macOS infostealer that harvests passwords, keychain data, browser credentials, and crypto wallets. The report highlights how leveraging trusted LLM outputs and legitimate platforms enables silent compromise without typical security warnings, and recommends focusing on behavioral detection (e.g., osascript anomalies, hidden executables) and user caution against copying terminal commands from unverified sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.