logo

ClickFix Campaign Evolves with Targeting of MacOS Users

ID: 0f67a1ea-7e8a-5985-a30b-1def4ab094ab

STIX ID: report--0f67a1ea-7e8a-5985-a30b-1def4ab094ab

Feed Name: The Cyber Express

Threat Score
78/100

Date Published: 2026-05-07

Date Updated: 2026-05-08

Author: Mihir Bagwe

...
...

ClickFix is an active macOS-focused social-engineering campaign that lures users into pasting malicious commands into Terminal or using Script Editor, which then deploy in-memory loaders or Mach-O droppers to install infostealers (Macsync, Shub Stealer, AMOS). The malware harvests Keychain entries, iCloud data, media, and crypto wallet keys, uses region-based kill switches to avoid CIS targets and researchers, and adapts to bypass Apple’s Terminal paste warnings; defenders are advised to monitor Terminal/osascript activity and protect credential stores.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.