Threats & Adversaries · Web App Attack

Macfinger Uses Legitimate Sites to Target macOS

SANS Internet Storm Center said it found several legitimate websites carrying injected scripts for the Macfinger ClickFix campaign, which it saw on September 22, 2026. The lure only showed up for macOS visitors, making the campaign selective rather than a broad spray of fake warnings.

The injected page first fingerprints the device, then serves a fake bot-protection or verification prompt that pushes the user through ClickFix-style social engineering. While the victim follows the steps, the victim host keeps talking to the campaign infrastructure and malware is fetched behind the scenes, so the traffic can blend into normal HTTPS noise.

That selective delivery means broad web filtering and generic user reports can miss the campaign if non-macOS visitors never see the lure. If a compromised site is only testing the right browser and operating system before showing the prompt, the exposure sits at the site layer and the browser-session layer, not just on the endpoint.

1 source · 6h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-09-23

Every edition of this story: Macfinger Uses Legitimate Sites to Target macOS

More from today