logo

Fake macOS Troubleshooting Sites Used to Steal iCloud Data in ClickFix Scam

ID: 482ca54f-9423-5c3b-819f-fe36ec7b7969

STIX ID: report--482ca54f-9423-5c3b-819f-fe36ec7b7969

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-05-08

Date Updated: 2026-05-11

Author: Deeba Ahmed

...
...

Microsoft Defender Security Research Team analyzed a ClickFix campaign that uses fake troubleshooting guides to trick Mac users into pasting Terminal commands that download and execute infostealer malware (examples: AMOS, Macsync, SHub Stealer). The malware harvests iCloud and Telegram data, private documents and photos, crypto wallet keys and saved browser credentials, can replace genuine crypto apps with trojanized versions, uses fileless execution to evade detection, and Apple added a macOS 26.4 warning to help block suspicious pasted commands.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.