ClickFix Style Attack Uses Grok, ChatGPT for Malware Delivery
ID: 1ab3ae93-9b5a-5dbb-af1b-721ece76dd02
STIX ID: report--1ab3ae93-9b5a-5dbb-af1b-721ece76dd02
Feed Name: Dark Reading
Huntress researchers describe a ClickFix-style campaign in which attackers poison search results and publish shared AI-chat conversations that instruct victims to run terminal commands; executing those commands installs AMOS, a persistent macOS infostealer that harvests passwords, keychain data, browser credentials, and crypto wallets. The report highlights how leveraging trusted LLM outputs and legitimate platforms enables silent compromise without typical security warnings, and recommends focusing on behavioral detection (e.g., osascript anomalies, hidden executables) and user caution against copying terminal commands from unverified sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
