logo

ClickFix campaign delivers Mac malware via fake Apple page

ID: 2c5aa040-503f-5229-a254-18c81cacb9ea

STIX ID: report--2c5aa040-503f-5229-a254-18c81cacb9ea

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-04-10

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

Jamf researchers uncovered a ClickFix-style campaign that lures macOS users to a fake Apple-themed webpage which, after prompting to open Script Editor, pre-populates and executes a malicious script that downloads and runs an Atomic Stealer (AMOS) variant capable of exfiltrating Keychain items, browser credentials, cookies, autofill data and cryptocurrency wallet information; indicators of compromise were shared.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.