The useful signal has moved off the page. This macOS ClickFix campaign now hides its lure behind a server-side browser check, so crawlers and sandboxes see less than a real Mac user does. That breaks detection that depends on page source or visible lure text.
Microsoft says the same infrastructure shifted from openly serving the malicious command in HTML to revealing it only to visitors that look like a genuine macOS browser. The campaign uses a large cluster of look-alike, algorithmically named domains and delivers MacSync and Atomic Stealer (AMOS). The new gate changes what defenders can see, so infrastructure patterns and fingerprinting behavior matter more than the lure itself.
Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam | Huntress
A ClickFix scam tricked a Mac user into running a Terminal command that installed Go-based malware able to steal Keychain passwords and drain crypto wallets.