Fake macOS Troubleshooting Sites Used to Steal iCloud Data in ClickFix Scam
ID: 482ca54f-9423-5c3b-819f-fe36ec7b7969
STIX ID: report--482ca54f-9423-5c3b-819f-fe36ec7b7969
Feed Name: HackRead
Microsoft Defender Security Research Team analyzed a ClickFix campaign that uses fake troubleshooting guides to trick Mac users into pasting Terminal commands that download and execute infostealer malware (examples: AMOS, Macsync, SHub Stealer). The malware harvests iCloud and Telegram data, private documents and photos, crypto wallet keys and saved browser credentials, can replace genuine crypto apps with trojanized versions, uses fileless execution to evade detection, and Apple added a macOS 26.4 warning to help block suspicious pasted commands.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
