Fake Homebrew, LogMeIn, and TradingView macOS developer campaign
Campaign
Summary
Hide ▲
Show ▼
A malicious campaign is targeting macOS developers with fake Homebrew, LogMeIn, and TradingView sites, creating a broad infostealer risk for Apple users. The operation uses ClickFix lures and search promotion to push victims into running Terminal commands that install AMOS and Odyssey.
Related Happenings
DriveSurge large-scale website-hijack malware distribution campaign
Campaign
H score41
First: 02.06.2026 01:14
Last: 02.06.2026 01:14
Sources 1
About this happening:
The DriveSurge campaign is redirecting visitors from thousands of compromised websites to malware-delivery infrastructure, creating a broad infection path through Cl...
DriveSurge large-scale website-hijack malware distribution campaign
CampaignAbout this happening: The DriveSurge campaign is redirecting visitors from thousands of compromised websites to malware-delivery infrastructure, creating a broad infection path through Cl...
MacOS living-off-the-land analysis exposing native-feature abuse
Technical Analysis
H score20
First: 22.04.2026 19:30
Last: 22.04.2026 19:30
Sources 1
About this happening:
Native macOS features are now being repurposed for code execution, lateral movement, and evasion, widening detection gaps across enterprise Apple fleets. The analysis...
MacOS living-off-the-land analysis exposing native-feature abuse
Technical AnalysisAbout this happening: Native macOS features are now being repurposed for code execution, lateral movement, and evasion, widening detection gaps across enterprise Apple fleets. The analysis...
MacOS LOTL detection and hardening guidance against native-tool abuse
Defensive Guidance
H score17
First: 22.04.2026 19:30
Last: 22.04.2026 19:30
Sources 1
About this happening:
Defensive guidance now pushes macOS security teams to detect native-tool abuse by shifting toward process lineage analysis, because attackers are using built-in features t...
MacOS LOTL detection and hardening guidance against native-tool abuse
Defensive GuidanceAbout this happening: Defensive guidance now pushes macOS security teams to detect native-tool abuse by shifting toward process lineage analysis, because attackers are using built-in features t...
Atomic Stealer (AMOS) macOS ClickFix Script Editor activity
Malware Activity
H score30
First: 09.04.2026 14:20
Last: 09.04.2026 14:20
Sources 1
About this happening:
A macOS malware campaign has shifted its ClickFix execution flow to Script Editor, helping Atomic Stealer (AMOS) avoid the usual Terminal warning path. The cha...
Atomic Stealer (AMOS) macOS ClickFix Script Editor activity
Malware ActivityAbout this happening: A macOS malware campaign has shifted its ClickFix execution flow to Script Editor, helping Atomic Stealer (AMOS) avoid the usual Terminal warning path. The cha...
Atomic Stealer macOS Script Editor ClickFix campaign
Campaign
H score42
First: 08.04.2026 21:55
Last: 08.04.2026 21:55
Sources 1
About this happening:
A new Atomic Stealer (AMOS) campaign is targeting macOS users through fake Apple-themed cleanup sites, creating a lower-friction path to malware installation and data...
Atomic Stealer macOS Script Editor ClickFix campaign
CampaignAbout this happening: A new Atomic Stealer (AMOS) campaign is targeting macOS users through fake Apple-themed cleanup sites, creating a lower-friction path to malware installation and data...
Timeline
-
18.10.2025 18:02 2 articles · 9mo ago
Researchers disclose fake Homebrew, LogMeIn, and TradingView macOS developer campaign
Initial DisclosureHunt.io identified more than 85 domains impersonating Homebrew, LogMeIn, and TradingView to target macOS developers with ClickFix-style lures. The malicious sites present fake download portals and connection-check prompts that push victims to copy curl commands into Terminal, sometimes swapping the visible Cloudflare verification text for a base64-encoded installation command. The delivery chain fetches install.sh, drops AMOS (Atomic macOS Stealer) or Odyssey, removes quarantine flags to bypass Gatekeeper, and can exfiltrate browser, cryptocurrency, Keychain, and file data; some traffic to the lookalike domains was driven through Google Ads.
Show sources
- Google ads for fake Homebrew, LogMeIn sites push infostealers — www.bleepingcomputer.com — 18.10.2025 18:02
- Google ads for fake Homebrew, LogMeIn sites push infostealers — www.bleepingcomputer.com — 18.10.2025 18:02