ClickFix Uses Fingerprinting to Target Mac Users

The Hacker News · High sophistication
Last updated August 5, 2026

Microsoft tracked a real macOS ClickFix campaign using 250+ domains that fingerprint visitors to hide malicious pages from security scanners. Selected Mac users are shown a fake “Download for macOS” lure and prompted to copy/paste an obfuscated command into Terminal, which then pulls down scripts and installs an infostealer (AMOS) to steal credentials and sensitive data.

Key findings

  • Microsoft observed a macOS ClickFix operation using 250+ front-end domains and a server-side fingerprinting “gate” to decide who sees the malware lure.
  • Qualified visitors see a GitHub-themed fake download page with a forged trust signal (“Verified Publisher”).
  • The attack depends on user action: victims are instructed to copy and run an obfuscated command in Terminal.
  • After execution, the command fetches more scripts and launches Atomic Stealer (AMOS), targeting credentials, browser data, crypto wallets, and sensitive files.
  • The infrastructure is designed to evade analysis by serving different content to crawlers/sandboxes versus real Mac users.

Who’s being targeted

  • Commonly targeted roles: All macOS users, Executives, Finance, Anyone handling credentials or cryptocurrency wallets, IT helpdesk (for triage and user coaching).
  • Attack channels: website.
  • Impersonated: GitHub-themed software download page (with a forged trust badge).

Awareness takeaways

  • Treat any site instruction to paste/run Terminal commands as a major warning sign and stop immediately.
  • Do not assume a site is safe just because it looks normal once, attackers can show different pages to different visitors.
  • Train employees to be suspicious of fake download pages using trust badges or “verified publisher” claims as persuasion.
  • If a user ran a pasted command, treat it as a potential credential theft incident and respond quickly.

Red flags to watch for

  • A website instructs the user to paste/run commands in Terminal
  • Overly generic trust signals like a forged “Verified Publisher” badge
  • Download flow depends on running a command rather than a normal installer/app store step
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

On your Mac, you click a link and land on a slick GitHub-style page: big blue button, “Download for macOS.” Looks totally legit. Behind the scenes, ClickFix is fingerprinting you. If you look like a real Mac user, it shows a forged “Verified Publisher” badge and tells you: copy this weird command into Terminal to continue. Here’s the trap: that one pasted command quietly pulls down more scripts and launches Atomic Stealer, ripping passwords, browser data, even crypto wallets off your Mac. Aha rule: any website that tells you to paste a command into Terminal? Stop. Close the tab. Then report it to security and say you hit a fake macOS download asking for Terminal.

Similar attacks

Cloudflare Workers Used to Steal MFA Sessions

Cloudflare Workers Used to Steal MFA Sessions

A real multi-stage phishing campaign abused trusted cloud platforms (notably Cloudflare Workers) to make fake login flows look legitimate and to bypass MFA. The attack chained a phishing email, a fake CAPTCHA page on a compromised site, and a browser “pop-up” spoof that captured both credentials…

August 4, 2026
Cybercrime as a Service Fuels New Scam Waves

Cybercrime as a Service Fuels New Scam Waves

A threat landscape report describes how criminals now buy or rent phishing, fraud, malware, and hidden infrastructure “as a service,” making scams faster to launch and harder to stop. The article highlights practical, repeatable social-engineering workflows such as fake CAPTCHA pages that trick…

July 31, 2026
Device Code Phishing: MFA Bypass at Scale

Device Code Phishing: MFA Bypass at Scale

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access without stealing passwords. It highlights rapid criminal adoption via phishing-as-a-service kits and notes heavy targeting of Microsoft…

July 31, 2026
Fake Install Guides and Helpdesk Calls Drive Attacks

Fake Install Guides and Helpdesk Calls Drive Attacks

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result “install guide,” a recruiter outreach, or a helpdesk phone call. The lures push victims to paste commands, install fake software, or reset MFA,…

July 30, 2026
Fake Download Sites Hijack Clicks to Drop Malware

Fake Download Sites Hijack Clicks to Drop Malware

Researchers and a Windows app developer uncovered a campaign using lookalike “official” software download websites that rank highly in Google results. The sites initially serve legitimate downloads to build trust, then quietly swap the download links to malware that can steal credentials and…

July 29, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026