logo

ClickFix Campaigns Spread MacSync macOS Infostealer via Fake AI Tool Installers

ID: 9e2a0ee2-f875-5377-9354-7e867fa136ab

STIX ID: report--9e2a0ee2-f875-5377-9354-7e867fa136ab

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-03-16

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A series of widespread ClickFix/InstallFix campaigns use malicious search ads, compromised and legitimate hosting platforms, and social-engineered terminal/PowerShell paste commands to deploy macOS and Windows infostealers (e.g., MacSync, Alien, Atomic). Campaigns employ sophisticated evasion (in-memory AppleScript payloads, obfuscated loaders), target developer/macOS users to harvest credentials, keychains, and crypto seed phrases, and leverage TDS/infected WordPress sites to scale distribution across multiple countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.