MacOS ClickFix Terminal-delivered DMG campaign
Campaign
Summary
Hide ▲
Show ▼
A macOS ClickFix campaign is using fake CAPTCHA pages and Terminal commands to quietly download and launch malicious DMG files, putting Mac devices at risk of AMOS credential theft. The operation expands the attack surface by turning a browser prompt into a malware delivery chain that can steal passwords, wallets, and other user data.
Related Happenings
CrashStealer macOS information stealer activity
Malware Activity
H score10
First: 13.07.2026 20:36
Last: 13.07.2026 20:36
Sources 1
About this happening:
CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...
CrashStealer macOS information stealer activity
Malware ActivityAbout this happening: CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...
MacOS.Gaslight prompt-injection technique aimed at AI-assisted triage
Technical Analysis
H score23
First: 24.06.2026 17:00
Last: 24.06.2026 17:00
Sources 1
About this happening:
macOS.Gaslight is a Rust-based macOS implant and information stealer assessed with high confidence as the work of North Korea-aligned threat actors. The sample uses ...
MacOS.Gaslight prompt-injection technique aimed at AI-assisted triage
Technical AnalysisAbout this happening: macOS.Gaslight is a Rust-based macOS implant and information stealer assessed with high confidence as the work of North Korea-aligned threat actors. The sample uses ...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware Activity
H score13
First: 18.06.2026 18:00
Last: 18.06.2026 18:00
Sources 1
About this happening:
A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware ActivityAbout this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
SilabRAT session-hijacking crypto-draining malware activity
Malware Activity
H score24
First: 10.06.2026 18:30
Last: 10.06.2026 18:30
Sources 1
About this happening:
The SilabRAT MaaS operation is now offering a session-hijacking remote access trojan that can drain cryptocurrency and bypass password and MFA checks, expandin...
SilabRAT session-hijacking crypto-draining malware activity
Malware ActivityAbout this happening: The SilabRAT MaaS operation is now offering a session-hijacking remote access trojan that can drain cryptocurrency and bypass password and MFA checks, expandin...
DriveSurge as an initial access broker on a pay-per-install model
Threat Actor Meta
H score41
First: 02.06.2026 01:14
Last: 02.06.2026 01:14
Sources 1
About this happening:
DriveSurge has shifted into an initial access broker role built around a pay-per-install (PPI) model, expanding monetized access delivery and increasing downstream intrusi...
DriveSurge as an initial access broker on a pay-per-install model
Threat Actor MetaAbout this happening: DriveSurge has shifted into an initial access broker role built around a pay-per-install (PPI) model, expanding monetized access delivery and increasing downstream intrusi...
Timeline
-
23.06.2026 21:30 2 articles · 22d ago
Fake CAPTCHA Terminal commands deliver Atomic macOS Stealer on Mac devices
Initial DisclosurePalo Alto Networks Unit 42 identified a macOS ClickFix campaign that uses fake CAPTCHA pages and Terminal commands to quietly download, mount, and launch malicious DMG payloads on Mac devices. The campaign delivers Atomic macOS Stealer (AMOS), which steals browser credentials, cryptocurrency wallet data, Keychain data, messaging app information, and user documents, and it uses a download-and-launch chain that hides the DMG mount and then uploads harvested data to attacker infrastructure.
Show sources
- New macOS ClickFix attack silently mounts DMGs to push infostealer — www.bleepingcomputer.com — 23.06.2026 21:30
- New macOS ClickFix attack silently mounts DMGs to push infostealer — www.bleepingcomputer.com — 23.06.2026 21:30