logo

ClickFix finds a new way to infect Macs

ID: 08713c57-9044-5020-b620-64e2de284fd6

STIX ID: report--08713c57-9044-5020-b620-64e2de284fd6

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2026-04-10

Date Updated: 2026-04-28

...
...

ClickFix campaigns are leveraging the applescript:// deep link to open Script Editor with pre-filled scripts that run obfuscated curl | zsh chains, pulling and executing Atomic Stealer (AMOS) or similar macOS infostealers; this replaces the older Terminal copy-paste lure and increases the likelihood of users granting permissions and infecting their own systems. The report describes how the technique works, notes ClickFix's large share of loader activity, and provides user-focused mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.