ClickFix finds a new way to infect Macs
ID: 08713c57-9044-5020-b620-64e2de284fd6
STIX ID: report--08713c57-9044-5020-b620-64e2de284fd6
Feed Name: Malwarebytes Blog
ClickFix campaigns are leveraging the applescript:// deep link to open Script Editor with pre-filled scripts that run obfuscated curl | zsh chains, pulling and executing Atomic Stealer (AMOS) or similar macOS infostealers; this replaces the older Terminal copy-paste lure and increases the likelihood of users granting permissions and infecting their own systems. The report describes how the technique works, notes ClickFix's large share of loader activity, and provides user-focused mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
