logo

Fake Codex Download Uses Google Sites to Deliver macOS Malware

ID: 95490994-0245-5acc-9350-7885f85932c6

STIX ID: report--95490994-0245-5acc-9350-7885f85932c6

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

...
...

Cato Networks researchers found a fake OpenAI Codex download campaign that used sponsored search ads and Google Sites pages to deliver a ClickFix-style paste-and-run Terminal command on macOS; the command fetched a multi-stage shell loader which decoded and retrieved a universal Mach-O payload, with staging in /tmp/helper and removal of quarantine attributes. The delivery infrastructure used iframes, OS- and path-based gating to evade analysis, and showed substantial overlap with the AMOS delivery framework, meaning defenders must correlate sponsored-search delivery, embedded web content, Terminal execution and outbound activity to detect it.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.