logo

macOS ClickFix Social Engineering Campaigns

ID: 10f7bdf3-0848-55b4-a831-4bd2028f3ab1

STIX ID: report--10f7bdf3-0848-55b4-a831-4bd2028f3ab1

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
78/100

Date Published: 2026-06-04

Date Updated: 2026-06-05

Author: Maor Gabay

...
...

The report details the ClickFix campaign, a macOS-targeted, human-centric attack that leverages high-fidelity social engineering (fake troubleshooting pages, typosquatted domains, and one-click applescript vectors) to trick users into running obfuscated curl/zsh commands. Adversaries have delivered diverse infostealers and RAT functionality (AMOS, Cuckoo, SHub), used CVE-2026-26980 to inject loaders into large numbers of domains, and employed sophisticated evasion (Gatekeeper bypass via Script Editor, sandbox detection, dynamic C2, self-destruct) to exfiltrate credentials, keychains, messaging tokens, and cryptocurrency wallets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.