logo

Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings

ID: d030b020-f316-5bf8-b89d-23e4fe6a6a3b

STIX ID: report--d030b020-f316-5bf8-b89d-23e4fe6a6a3b

Feed Name: Infosecurity Magazine (News)

Threat Score
65/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

...
...

A macOS malware campaign delivering the Atomic Stealer (AMOS) has shifted its execution vector from Terminal to Script Editor to evade macOS 26.4's paste-warnings for ClickFix attacks; attackers present fake Apple guidance in the browser to trick users into pasting malicious commands. Jamf Threat Labs identified the campaign, which functions as an infostealer/backdoor, and recommends mitigations such as restricting clipboard/run-dialog use and blocking malicious sites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.