Cloaked Mac ClickFix Sites Push Terminal Infostealers

Microsoft Secure · High sophistication
Last updated August 5, 2026

Microsoft Threat Intelligence tracked a real macOS “ClickFix” campaign that uses look‑alike domains to trick Mac users into copying and running a Terminal command. The operation now hides the malicious “Download for macOS” lure behind server-side browser fingerprinting, showing benign decoy pages to scanners and non‑Mac visitors while delivering infostealers like Atomic Stealer (AMOS) to likely Mac targets.

Key findings

  • Campaign distributes macOS information stealers including MacSync and Atomic Stealer (AMOS).
  • Operators shifted from openly serving the malicious command in page HTML to a server-side fingerprinting gate that selectively reveals the lure to likely macOS visitors.
  • Same URL can show either the ClickFix lure or a benign decoy (e.g., fake VPN/extension landing page), reducing defender visibility and complicating investigation.
  • Lure is a fake “Download for macOS” page with a forged “Verified Publisher” badge and a one-click copy of an obfuscated curl one-liner that users are instructed to run in Terminal.
  • Domain infrastructure includes mass-produced, dictionary-style look-alike names (often using the token “file”).

Who’s being targeted

  • Commonly targeted roles: All employees who use macOS, Executives and assistants (frequent web downloads), IT helpdesk and desktop support, Security awareness training audience, Security operations/Threat hunting (for cloaking/TDS awareness).
  • Affected industries: Any organization with macOS endpoints.
  • Attack channels: website.
  • Impersonated: A macOS software publisher/download site (with a forged trust badge), A benign product or business website (e.g., VPN/extension landing page or unrelated company site).

Awareness takeaways

  • Treat any site that tells you to paste and run Terminal commands to “complete a download” as suspicious, stop and verify through official vendor channels.
  • Don’t trust “verified/publisher” badges or polished download pages by themselves; verify the domain and source before downloading or running anything.
  • Security teams should not assume a domain is safe just because automated scans show benign content; cloaking can hide the real lure from crawlers and sandboxes.
  • macOS users should be trained to recognize “Download for macOS” lures and report them immediately, especially if the page offers a one-click copy command.

Red flags to watch for

  • Website asks you to run a Terminal command instead of installing a normal macOS app
  • Trust indicator looks fake (e.g., forged “Verified Publisher” badge)
  • Domain name looks random/dictionary-generated or unrelated to the software being downloaded
  • Same URL can show different content depending on device/browser
  • Site appears blank/parked or unrelated to the domain purpose
  • Benign-looking content may still be hosted on malicious infrastructure
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

On your Mac, you hit a site that says “Verified Publisher – Download for macOS”… and asks you to run a Terminal command. This is ClickFix: a Mac scam where sites like apricotfilepoint dot com trick you into copying a curl one‑liner into Terminal, silently dropping infostealers like Atomic Stealer and MacSync. The aha: a legit Mac app does NOT need you to paste mystery commands into Terminal to ‘complete the download’, that’s the ClickFix tell, no matter how shiny the page or badge looks. If any download page tells you to copy a Terminal command, stop. Don’t run it, report the site to Security, then get the app only from the official vendor or App Store.

Similar attacks

Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
Fake CAPTCHA ‘ClickFix’ Drops Cruciferra Malware

Fake CAPTCHA ‘ClickFix’ Drops Cruciferra Malware

A real malware campaign used compromised websites to show fake CAPTCHA/verification pages that tricked people into copying and running a PowerShell command themselves. That manual “copy/paste” step helped the attackers bypass normal download defenses and install the Cruciferra loader, which then…

August 25, 2026
Korea Flags Job-Offer Phish + Watering Holes

Korea Flags Job-Offer Phish + Watering Holes

South Korean agencies warned that a state-backed hacking group is actively targeting citizens and businesses using job-themed phishing emails and “watering hole” attacks on legitimate websites. The phishing lures include fake job applicants sending resume links and impersonated recruiters sending…

July 31, 2026
ClickFix Trick Spreads ACR Stealer via Paste-Run

ClickFix Trick Spreads ACR Stealer via Paste-Run

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR (Amatera) Stealer. The malware steals saved browser passwords, live session tokens, and Microsoft 365/OneDrive/SharePoint files, meaning…

July 17, 2026
Sandworm Uses Fake CAPTCHAs to Spread Malware

Sandworm Uses Fake CAPTCHAs to Spread Malware

Ukraine’s CERT says the Russia-linked Sandworm group is tricking targets into infecting their own PCs using compromised websites that display fake CAPTCHA checks. Victims are instructed to copy and paste a PowerShell command, which downloads malware and can lead to deeper compromise. CERT also…

July 16, 2026
Fake SSO + MFA Push Used in Real Breaches

Fake SSO + MFA Push Used in Real Breaches

This weekly roundup includes two real social-engineering-driven incidents. Attackers used social engineering to access Apollo Global Management’s cloud platforms and steal sensitive personal data, and separately attempted a ShinyHunters phishing attack against ReliaQuest using a fake SSO login page…

August 28, 2026