ClickFix Uses Fingerprinting to Target Mac Users

The Hacker News · High sophistication
Last updated August 5, 2026

Microsoft tracked a real macOS ClickFix campaign using 250+ domains that fingerprint visitors to hide malicious pages from security scanners. Selected Mac users are shown a fake “Download for macOS” lure and prompted to copy/paste an obfuscated command into Terminal, which then pulls down scripts and installs an infostealer (AMOS) to steal credentials and sensitive data.

Key findings

  • Microsoft observed a macOS ClickFix operation using 250+ front-end domains and a server-side fingerprinting “gate” to decide who sees the malware lure.
  • Qualified visitors see a GitHub-themed fake download page with a forged trust signal (“Verified Publisher”).
  • The attack depends on user action: victims are instructed to copy and run an obfuscated command in Terminal.
  • After execution, the command fetches more scripts and launches Atomic Stealer (AMOS), targeting credentials, browser data, crypto wallets, and sensitive files.
  • The infrastructure is designed to evade analysis by serving different content to crawlers/sandboxes versus real Mac users.

Who’s being targeted

  • Commonly targeted roles: All macOS users, Executives, Finance, Anyone handling credentials or cryptocurrency wallets, IT helpdesk (for triage and user coaching).
  • Attack channels: website.
  • Impersonated: GitHub-themed software download page (with a forged trust badge).

Awareness takeaways

  • Treat any site instruction to paste/run Terminal commands as a major warning sign and stop immediately.
  • Do not assume a site is safe just because it looks normal once, attackers can show different pages to different visitors.
  • Train employees to be suspicious of fake download pages using trust badges or “verified publisher” claims as persuasion.
  • If a user ran a pasted command, treat it as a potential credential theft incident and respond quickly.

Red flags to watch for

  • A website instructs the user to paste/run commands in Terminal
  • Overly generic trust signals like a forged “Verified Publisher” badge
  • Download flow depends on running a command rather than a normal installer/app store step
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

On your Mac, you click a link and land on a slick GitHub-style page: big blue button, “Download for macOS.” Looks totally legit. Behind the scenes, ClickFix is fingerprinting you. If you look like a real Mac user, it shows a forged “Verified Publisher” badge and tells you: copy this weird command into Terminal to continue. Here’s the trap: that one pasted command quietly pulls down more scripts and launches Atomic Stealer, ripping passwords, browser data, even crypto wallets off your Mac. Aha rule: any website that tells you to paste a command into Terminal? Stop. Close the tab. Then report it to security and say you hit a fake macOS download asking for Terminal.

Similar attacks

Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Researchers say a real macOS malware campaign is using “ClickFix” social engineering to trick users into installing an infostealer called AmnesiaStealer. Victims are lured to a counterfeit GitHub download page that encourages them to copy/paste a Terminal command, which then downloads and runs the…

August 14, 2026
AI Brands Used as Bait in Phishing Waves

AI Brands Used as Bait in Phishing Waves

Microsoft Threat Intelligence reports real campaigns where attackers impersonate popular AI tools (like ChatGPT, Copilot, DeepSeek, and Claude) to trick people into clicking links, installing fake software, or entering payment and login details. One campaign sent up to 100,000 emails in a day to…

September 10, 2026
Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
Fake SSO + MFA Push Used in Real Breaches

Fake SSO + MFA Push Used in Real Breaches

This weekly roundup includes two real social-engineering-driven incidents. Attackers used social engineering to access Apollo Global Management’s cloud platforms and steal sensitive personal data, and separately attempted a ShinyHunters phishing attack against ReliaQuest using a fake SSO login page…

August 28, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026