Fake Codex Download Uses Google Sites to Deliver macOS Malware
ID: 95490994-0245-5acc-9350-7885f85932c6
STIX ID: report--95490994-0245-5acc-9350-7885f85932c6
Feed Name: Infosecurity Magazine (News)
Cato Networks researchers found a fake OpenAI Codex download campaign that used sponsored search ads and Google Sites pages to deliver a ClickFix-style paste-and-run Terminal command on macOS; the command fetched a multi-stage shell loader which decoded and retrieved a universal Mach-O payload, with staging in /tmp/helper and removal of quarantine attributes. The delivery infrastructure used iframes, OS- and path-based gating to evade analysis, and showed substantial overlap with the AMOS delivery framework, meaning defenders must correlate sponsored-search delivery, embedded web content, Terminal execution and outbound activity to detect it.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
