Microsoft Threat Intelligence tracked a macOS ClickFix campaign distributing AMOS and MacSync infostealers through 250+ algorithmically named domains. The campaign evolved from openly embedding malicious Terminal commands in HTML to deploying a server-side browser-fingerprinting gate (TDS) that only serves the ClickFix lure to visitors presenting a genuine macOS browser fingerprint, significantly reducing visibility for automated scanners and researchers. The infection chain uses social engineering to trick users into running curl-piped-to-shell commands that download and execute AMOS, which exfiltrates credentials, browser data, and cryptocurrency wallets.
macOS infostealer
2 posts
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites A large-scale ClickFix campaign compromises hundreds of WordPress websites to deliver a macOS infostealer via fake Cloudflare CAPTCHA overlays. The campaign uses a Polygon blockchain smart contract to store the C2 URL, making it resistant to DNS takedowns. Victims are tricked into pasting a Terminal command that downloads an in-memory payload via curl, which uses osascript to harvest Keychain data, browser credentials, SSH keys, and screenshots before exfiltrating them in chunks to an attacker-controlled server.