logo

ClickFix campaign uses fake macOS utilities lures to deliver infostealers

ID: a5832945-2517-5b9a-99e7-38aceae703ec

STIX ID: report--a5832945-2517-5b9a-99e7-38aceae703ec

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Microsoft Defender Security Research Team and Microsoft Defender Experts

...
...

Microsoft describes an active macOS-focused infostealer campaign (ClickFix) that lures users into pasting Base64-encoded Terminal commands hosted on blogs and note platforms; these commands load in-memory AppleScript or shell loaders that install infostealers (MacSync, SHub, AMOS), steal Keychain, browser and iCloud data, exfiltrate cryptocurrency wallets, and sometimes replace wallet apps with trojanized versions. The report details three execution paths (loader, script, helper), persistence via LaunchAgents/LaunchDaemons, C2 discovery (including Telegram fallback), extensive IoCs (domains, IPs, hashes, file paths), and recommended detection and mitigation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.