macOS ClickFix Social Engineering Campaigns
ID: 10f7bdf3-0848-55b4-a831-4bd2028f3ab1
STIX ID: report--10f7bdf3-0848-55b4-a831-4bd2028f3ab1
Feed Name: LevelBlue SpiderLabs Blog
The report details the ClickFix campaign, a macOS-targeted, human-centric attack that leverages high-fidelity social engineering (fake troubleshooting pages, typosquatted domains, and one-click applescript vectors) to trick users into running obfuscated curl/zsh commands. Adversaries have delivered diverse infostealers and RAT functionality (AMOS, Cuckoo, SHub), used CVE-2026-26980 to inject loaders into large numbers of domains, and employed sophisticated evasion (Gatekeeper bypass via Script Editor, sandbox detection, dynamic C2, self-destruct) to exfiltrate credentials, keychains, messaging tokens, and cryptocurrency wallets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
