logo

Tech impersonators: ClickFix and MacOS infostealers

ID: 27de4f18-327f-570e-90c3-31b1c7c05e9c

STIX ID: report--27de4f18-327f-570e-90c3-31b1c7c05e9c

Feed Name: Datadog Security Labs

Threat Score
75/100

Date Published: 2026-02-10

Date Updated: 2026-04-27

...
...

Datadog Security Research identifies an ongoing campaign using impersonating GitHub repositories and ClickFix pages to trick users into running paste-to-shell commands that deploy macOS infostealers (MacSync and the more advanced SHub v2.0). SHub adds credential validation, expanded wallet and enterprise data collection, persistence as a fake GoogleUpdate LaunchAgent, and periodic C2 heartbeat/remote command execution. The report includes detailed TTPs, sample staging scripts, C2 domains and endpoints, GitHub lures, temporary file locations, actor accounts, and mitigation guidance (source verification, repository validation, command scrutiny, user awareness).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.