Cloaked Mac ClickFix Sites Push Terminal Infostealers

Microsoft Secure · High sophistication
Last updated August 5, 2026

Microsoft Threat Intelligence tracked a real macOS “ClickFix” campaign that uses look‑alike domains to trick Mac users into copying and running a Terminal command. The operation now hides the malicious “Download for macOS” lure behind server-side browser fingerprinting, showing benign decoy pages to scanners and non‑Mac visitors while delivering infostealers like Atomic Stealer (AMOS) to likely Mac targets.

Key findings

  • Campaign distributes macOS information stealers including MacSync and Atomic Stealer (AMOS).
  • Operators shifted from openly serving the malicious command in page HTML to a server-side fingerprinting gate that selectively reveals the lure to likely macOS visitors.
  • Same URL can show either the ClickFix lure or a benign decoy (e.g., fake VPN/extension landing page), reducing defender visibility and complicating investigation.
  • Lure is a fake “Download for macOS” page with a forged “Verified Publisher” badge and a one-click copy of an obfuscated curl one-liner that users are instructed to run in Terminal.
  • Domain infrastructure includes mass-produced, dictionary-style look-alike names (often using the token “file”).

Who’s being targeted

  • Commonly targeted roles: All employees who use macOS, Executives and assistants (frequent web downloads), IT helpdesk and desktop support, Security awareness training audience, Security operations/Threat hunting (for cloaking/TDS awareness).
  • Affected industries: Any organization with macOS endpoints.
  • Attack channels: website.
  • Impersonated: A macOS software publisher/download site (with a forged trust badge), A benign product or business website (e.g., VPN/extension landing page or unrelated company site).

Awareness takeaways

  • Treat any site that tells you to paste and run Terminal commands to “complete a download” as suspicious, stop and verify through official vendor channels.
  • Don’t trust “verified/publisher” badges or polished download pages by themselves; verify the domain and source before downloading or running anything.
  • Security teams should not assume a domain is safe just because automated scans show benign content; cloaking can hide the real lure from crawlers and sandboxes.
  • macOS users should be trained to recognize “Download for macOS” lures and report them immediately, especially if the page offers a one-click copy command.

Red flags to watch for

  • Website asks you to run a Terminal command instead of installing a normal macOS app
  • Trust indicator looks fake (e.g., forged “Verified Publisher” badge)
  • Domain name looks random/dictionary-generated or unrelated to the software being downloaded
  • Same URL can show different content depending on device/browser
  • Site appears blank/parked or unrelated to the domain purpose
  • Benign-looking content may still be hosted on malicious infrastructure
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

On your Mac, you hit a site that says “Verified Publisher – Download for macOS”… and asks you to run a Terminal command. This is ClickFix: a Mac scam where sites like apricotfilepoint dot com trick you into copying a curl one‑liner into Terminal, silently dropping infostealers like Atomic Stealer and MacSync. The aha: a legit Mac app does NOT need you to paste mystery commands into Terminal to ‘complete the download’, that’s the ClickFix tell, no matter how shiny the page or badge looks. If any download page tells you to copy a Terminal command, stop. Don’t run it, report the site to Security, then get the app only from the official vendor or App Store.

Similar attacks

Korea Flags Job-Offer Phish + Watering Holes

Korea Flags Job-Offer Phish + Watering Holes

South Korean agencies warned that a state-backed hacking group is actively targeting citizens and businesses using job-themed phishing emails and “watering hole” attacks on legitimate websites. The phishing lures include fake job applicants sending resume links and impersonated recruiters sending…

July 31, 2026
ClickFix Trick Spreads ACR Stealer via Paste-Run

ClickFix Trick Spreads ACR Stealer via Paste-Run

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR (Amatera) Stealer. The malware steals saved browser passwords, live session tokens, and Microsoft 365/OneDrive/SharePoint files, meaning…

July 17, 2026
Sandworm Uses Fake CAPTCHAs to Spread Malware

Sandworm Uses Fake CAPTCHAs to Spread Malware

Ukraine’s CERT says the Russia-linked Sandworm group is tricking targets into infecting their own PCs using compromised websites that display fake CAPTCHA checks. Victims are instructed to copy and paste a PowerShell command, which downloads malware and can lead to deeper compromise. CERT also…

July 16, 2026
ClickFix Uses Fingerprinting to Target Mac Users

ClickFix Uses Fingerprinting to Target Mac Users

Microsoft tracked a real macOS ClickFix campaign using 250+ domains that fingerprint visitors to hide malicious pages from security scanners. Selected Mac users are shown a fake “Download for macOS” lure and prompted to copy/paste an obfuscated command into Terminal, which then pulls down scripts…

August 5, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment failed” billing email to drive victims to a credit-card theft page. The report also notes other brand-impersonation scams using cloned stores…

July 24, 2026