Threats · 53 days ago
The useful signal has moved off the page. This macOS ClickFix campaign now hides its lure behind a server-side browser check, so crawlers and sandboxes see less than a real Mac user does. That breaks detection that depends on page source or visible lure text.
Microsoft says the same infrastructure shifted from openly serving the malicious command in HTML to revealing it only to visitors that look like a genuine macOS browser. The campaign uses a large cluster of look-alike, algorithmically named domains and delivers MacSync and Atomic Stealer (AMOS). The new gate changes what defenders can see, so infrastructure patterns and fingerprinting behavior matter more than the lure itself.
3 sources covering this story
Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam | Huntress
A ClickFix scam tricked a Mac user into running a Terminal command that installed Go-based malware able to steal Keychain passwords and drain crypto wallets.
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
A macOS ClickFix campaign uses more than 250 domains and server-side fingerprinting to hide AMOS lures from crawlers and serve selected Mac users.
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate.
Part of the PlainSec briefing for 2026-08-06