logo

Fake CleanMyMac Site Uses ClickFix Trick to Install SHub Stealer on macOS

ID: d73afd74-a2d7-52f4-97ea-889d4dd7c1d0

STIX ID: report--d73afd74-a2d7-52f4-97ea-889d4dd7c1d0

Feed Name: HackRead

Threat Score
72/100

Date Published: 2026-03-09

Date Updated: 2026-04-22

Author: Waqas

...
...

A fraudulent website impersonating CleanMyMac uses a ClickFix social-engineering trick to get macOS users to run a Terminal command that installs SHub Stealer. The malware bypasses Gatekeeper, performs locale-based geofencing to avoid Russian layouts, harvests system passwords and Keychain data via an AppleScript prompt, modifies popular cryptocurrency wallet applications to display fake recovery prompts and exfiltrate seed phrases, and establishes persistence with a LaunchAgent masquerading as Google’s Keystone updater.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.