logo

Google ads for shared ChatGPT, Grok guides push macOS infostealer malware

ID: 1f3025f2-7cd6-5cbe-8ca9-19c40cc38fea

STIX ID: report--1f3025f2-7cd6-5cbe-8ca9-19c40cc38fea

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-12-10

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A ClickFix campaign uses Google search ads to surface maliciously crafted ChatGPT and Grok conversations that trick macOS users into running terminal commands which deploy the AMOS infostealer. Once executed, the attack captures a provided password to run with elevated privileges, installs persistently as a hidden .helper, and harvests cryptocurrency wallets, browser data, keychain items, and other sensitive files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.