ClickFix Uses Fingerprinting to Target Mac Users

The Hacker News · High sophistication
Last updated August 5, 2026

Microsoft tracked a real macOS ClickFix campaign using 250+ domains that fingerprint visitors to hide malicious pages from security scanners. Selected Mac users are shown a fake “Download for macOS” lure and prompted to copy/paste an obfuscated command into Terminal, which then pulls down scripts and installs an infostealer (AMOS) to steal credentials and sensitive data.

Key findings

  • Microsoft observed a macOS ClickFix operation using 250+ front-end domains and a server-side fingerprinting “gate” to decide who sees the malware lure.
  • Qualified visitors see a GitHub-themed fake download page with a forged trust signal (“Verified Publisher”).
  • The attack depends on user action: victims are instructed to copy and run an obfuscated command in Terminal.
  • After execution, the command fetches more scripts and launches Atomic Stealer (AMOS), targeting credentials, browser data, crypto wallets, and sensitive files.
  • The infrastructure is designed to evade analysis by serving different content to crawlers/sandboxes versus real Mac users.

Who’s being targeted

  • Commonly targeted roles: All macOS users, Executives, Finance, Anyone handling credentials or cryptocurrency wallets, IT helpdesk (for triage and user coaching).
  • Attack channels: website.
  • Impersonated: GitHub-themed software download page (with a forged trust badge).

Awareness takeaways

  • Treat any site instruction to paste/run Terminal commands as a major warning sign and stop immediately.
  • Do not assume a site is safe just because it looks normal once, attackers can show different pages to different visitors.
  • Train employees to be suspicious of fake download pages using trust badges or “verified publisher” claims as persuasion.
  • If a user ran a pasted command, treat it as a potential credential theft incident and respond quickly.

Red flags to watch for

  • A website instructs the user to paste/run commands in Terminal
  • Overly generic trust signals like a forged “Verified Publisher” badge
  • Download flow depends on running a command rather than a normal installer/app store step
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

On your Mac, you click a link and land on a slick GitHub-style page: big blue button, “Download for macOS.” Looks totally legit. Behind the scenes, ClickFix is fingerprinting you. If you look like a real Mac user, it shows a forged “Verified Publisher” badge and tells you: copy this weird command into Terminal to continue. Here’s the trap: that one pasted command quietly pulls down more scripts and launches Atomic Stealer, ripping passwords, browser data, even crypto wallets off your Mac. Aha rule: any website that tells you to paste a command into Terminal? Stop. Close the tab. Then report it to security and say you hit a fake macOS download asking for Terminal.

Similar attacks

Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Researchers say a real macOS malware campaign is using “ClickFix” social engineering to trick users into installing an infostealer called AmnesiaStealer. Victims are lured to a counterfeit GitHub download page that encourages them to copy/paste a Terminal command, which then downloads and runs the…

August 14, 2026
Malicious Calendar Invites Surge With Malware Links

Malicious Calendar Invites Surge With Malware Links

Attackers are sending fake calendar meeting invites that can be automatically added to a victim’s calendar, even if the email is blocked. A documented example used a Google Calendar invite with a financial “invoice credit” lure to drive victims to a hosted webpage and download a malicious…

September 18, 2026
HBO Max Reddit Account Hijacked for ClickFix Malware Ads

HBO Max Reddit Account Hijacked for ClickFix Malware Ads

Attackers took over the verified official HBO Max Reddit account and used it to run a 48-hour wave of malicious ads. The ads sent people to lookalike download sites that tricked them into copying and running commands, leading to information-stealing malware on both macOS and Windows. Researchers…

September 15, 2026
NGOs Lured via Donation Form Into Chrome 0-Day Chain

NGOs Lured via Donation Form Into Chrome 0-Day Chain

Researchers reported two China-linked groups targeting NGOs with spear-phishing that led victims through a legitimate U.S. university website before redirecting them to attacker infrastructure. The attackers used a chained Chrome/Windows exploit to take control, then deployed different payloads,…

September 15, 2026
AI Brands Used as Bait in Phishing Waves

AI Brands Used as Bait in Phishing Waves

Microsoft Threat Intelligence reports real campaigns where attackers impersonate popular AI tools (like ChatGPT, Copilot, DeepSeek, and Claude) to trick people into clicking links, installing fake software, or entering payment and login details. One campaign sent up to 100,000 emails in a day to…

September 10, 2026