The useful signal has moved off the page. This macOS ClickFix campaign now hides its lure behind a server-side browser check, so crawlers and sandboxes see less than a real Mac user does. That breaks detection that depends on page source or visible lure text.
Microsoft says the same infrastructure shifted from openly serving the malicious command in HTML to revealing it only to visitors that look like a genuine macOS browser. The campaign uses a large cluster of look-alike, algorithmically named domains and delivers MacSync and Atomic Stealer (AMOS). The new gate changes what defenders can see, so infrastructure patterns and fingerprinting behavior matter more than the lure itself.