logo

From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

ID: 1d9f1cf9-f697-5fb9-af76-ab2a3aac2fe8

STIX ID: report--1d9f1cf9-f697-5fb9-af76-ab2a3aac2fe8

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2026-08-05

Date Updated: 2026-08-05

Author: Microsoft Security Research and Srinivasan Govindarajan

...
...

Microsoft Threat Intelligence observed a large macOS ClickFix campaign that mass-produces look-alike domains and uses a server-side browser‑fingerprinting gate to show malicious “Download for macOS” paste‑to‑Terminal lures only to qualified macOS browser visitors; the gated flow delivers infostealers including MacSync and Atomic Stealer (AMOS), and the report provides domain naming patterns, fingerprinting checks, the full infection chain, IOCs, and hunting/mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.