Threats · 131 days ago
macOS users do not need to install a suspicious app to get hit here. This campaign turns help content into the delivery path, getting victims to run malicious Terminal commands that load stealers and bypass the normal file-based defenses most teams watch for.
Microsoft says the activity has shifted from earlier .dmg-based delivery to ClickFix-style instructions embedded in user-driven sites. The payloads include Macsync, Shub Stealer, and AMOS, and they steal iCloud data, Keychain entries, media files, and crypto wallet keys; some variants also replace legitimate wallet apps with trojanized copies.
The forward risk is broader than one infostealer family. Any guidance or content that convinces a user to paste commands into Terminal can become a malware launcher, and a clean app inventory may no longer mean a clean Mac.
1 source covering this story
ClickFix campaign uses fake macOS utilities lures to deliver infostealers | Microsoft Security Blog
Threat actors are targeting macOS users with fake utility fixes that trick them into running malicious Terminal commands.
Part of the PlainSec briefing for 2026-05-06