Home icon Chevron Categories Chevron Blog Chevron News Chevron

New macOS Malware Campaign Uses ClickFix Trick to Target Apple Users

New macOS Malware Campaign Uses ClickFix Trick to Target Apple Users

June 06, 2025


Cybersecurity experts have uncovered a fresh malware campaign targeting macOS users through a social engineering technique known as ClickFix. This operation aims to deceive users into downloading a malicious software called Atomic macOS Stealer (AMOS), designed to steal sensitive information from Apple devices.

Researchers at CloudSEK report that the attackers exploit lookalike domains mimicking the U.S. telecom company Spectrum. These fake sites prompt visitors to complete a CAPTCHA to “verify security,” but when users attempt the check, they encounter a failure message pushing them toward an “Alternative Verification” process.

Accepting this alternative causes a command to be copied to the user’s clipboard, along with instructions to run certain commands based on their operating system. While Windows users are directed to execute a PowerShell command, macOS users are instructed to run a shell script via the Terminal app.

This shell script asks users for their system password and proceeds to download the Atomic Stealer malware, which uses native macOS commands to harvest credentials, bypass defenses, and install malicious files.

Security analyst Koushik Pal points out that the attackers made several errors in their setup, such as mixing instructions for Windows and macOS users, suggesting a rushed deployment.

The campaign appears linked to Russian-speaking cybercriminals, as indicated by Russian comments found in the malware code.

This ClickFix tactic, which manipulates users into running harmful commands disguised as routine verifications, has been increasingly observed in recent months. Attackers leverage this method to deliver a wide array of malware, including trojans, stealers, and ransomware.

The threat actors commonly use fake CAPTCHA pages that look identical to legitimate services such as Google reCAPTCHA or Cloudflare Turnstile. These pages sometimes appear on compromised websites, making them harder to detect.

Experts warn that users’ habitual quick-clicking on verification prompts, known as “verification fatigue,” is exploited by these campaigns to gain unauthorized access and steal data.

Similar campaigns have targeted organizations via email phishing, with malicious links leading victims to fake CAPTCHA pages that install remote access tools or information stealers.

Security firms have detected numerous ClickFix-based attacks across multiple regions, including Europe, the Middle East, Africa, and the United States, noting that the technique is flexible and increasingly popular among cybercriminals.

Stay informed. Stay secure.
—Cybersecurity88 Editorial Team

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news

Did you like the post? Share it in your media

Latest Articles

Featured

US and Canada Take Down Suspected KimWolf Botnet Admin in Massive Cybercrime Crackdown 

May 22, 2026 · Chetna Sehgal

A major cybercrime investigation by authorities in the United States and Canada has led to the ar...

Read More >
Featured

China-Linked Webworm Hackers Exploit Discord and Microsoft Graph to Target EU Governments

May 22, 2026 · Chetna Sehgal

China-linked cyber espionage group “Webworm” has recently been linked to a major hacking camp...

Read More >
Featured

Police Shut Down “First VPN” Used by Ransomware Gangs Worldwide 

May 21, 2026 · Chetna Sehgal

Police and international cybercrime agencies have shut down a VPN service called “First VPN” ...

Read More >
Featured

Content Delivery Exploit Opens Thousands of Trusted Websites to Brand Hijacking and Malicious Script Attacks 

May 21, 2026 · Chetna Sehgal

Cybersecurity researchers have recently warned about a serious attack method that is targeting we...

Read More >
Featured

Critical SEPPMail Vulnerabilities Expose Organizations to Remote Code Execution and Email Traffic Access 

May 19, 2026 · Chetna Sehgal

SEPPMail Secure E-Mail Gateway, a platform used by many organizations for encrypted and secure em...

Read More >
Featured

Critical Security Alert: Ivanti, Fortinet, SAP, VMware and n8n Patch Dangerous Vulnerabilities

May 18, 2026 · Chetna Sehgal

Several major technology companies including Ivanti, Fortinet, SAP, VMware, and n8n have released...

Read More >
Newsletter line