Evil evolution: ClickFix and macOS infostealers
ID: 14b34c15-ae59-577d-968b-3d4005a90c7f
STIX ID: report--14b34c15-ae59-577d-968b-3d4005a90c7f
Feed Name: Sophos Blogs
This report documents several ClickFix malvertising campaigns that lured macOS users through Google ads and shared ChatGPT conversations to GitHub-themed landing pages; victims were tricked into running terminal commands that fetched a multistage loader which deployed MacSync infostealer. The malware harvests browser data, keys, wallets and can patch Ledger Live to exfiltrate seed phrases, uses API-key gated C2, in-memory AppleScript execution, real-time victim tracking (stats.php → Telegram) and has recorded thousands of user interactions across multiple regions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
