- A macOS ClickFix campaign uses over 250 front-end domains to deliver information-stealing malware to targeted users.
- The attack employs a server-side fingerprinting gate that hides malicious pages from automated analysis tools and sandboxes.
- End targets are the MacSync and Atomic Stealer (AMOS) malware families, which steal credentials, browser data, and cryptocurrency wallet files.
- Apple’s macOS 26.4 introduces a Terminal confirmation prompt and improved XProtect tracing to defend against these paste-and-run command attacks.
Microsoft Threat Intelligence reported that a widespread macOS ClickFix campaign now uses over 250 front-end domains, deploying a server-side fingerprinting gate to determine whether a visitor receives a malware lure. The gate analyzes browser properties like platform, screen dimensions, and WebGL signals to filter out automated crawlers and sandbox environments before presenting a fake software download page.
Consequently, only users meeting the gate’s criteria—such as a genuine Mac device running a standard browser—see a fraudulent GitHub-themed page with a forged “Verified Publisher” badge. The attack chain ends in MacSync or Atomic Stealer (AMOS), infostealers targeting credentials, browser data, authentication stores, and cryptocurrency wallets, Microsoft detailed in an August 5 analysis.
Users must still comply by pasting an obfuscated Terminal command that fetches remote scripts, a step Microsoft says is unchanged from earlier campaigns. Apple responded with macOS 26.4, which adds a confirmation prompt for users pasting commands from browsers or messaging apps, and enhanced XProtect tracing that can inspect process trees and network artifacts to block known malware activity.
Microsoft advised defenders to hunt for the fingerprinting gate itself—watching for self-submitting fingerprint forms and the “mode:php” artifact—rather than chasing the disposable front-end domains. The operation extends a shift Microsoft documented in May, when macOS infostealer campaigns began using Terminal commands to fetch remote scripts instead of shipping a disk image to install by hand.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
