logo

Fake Homebrew Pages Deliver Cuckoo Stealer via ClickFix

ID: 9f1b5960-afcb-5a22-964d-ff50bf3bf2f2

STIX ID: report--9f1b5960-afcb-5a22-964d-ff50bf3bf2f2

Feed Name: Hunt.io Blog

Threat Score
78/100

Date Published: 2026-02-18

Date Updated: 2026-04-28

...
...

Attackers operate a ClickFix campaign that typosquats Homebrew download pages to trick macOS developers into running a modified installer; the initial script loops to harvest valid user passwords and installs Cuckoo Stealer, a persistent macOS infostealer/RAT that removes quarantine flags, uses encrypted HTTPS C2 with X25519/MD5-derived XOR encryption, and exfiltrates Keychain, browser/extension data (notably crypto wallets), messaging sessions, VPN/FTP credentials, and local documents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.