Find notable cyber news and cases, enriched with sources, timelines, and signals.

Fake Codex download campaign using Google Sites and ClickFix

Campaign
First reported
Last updated
Happening score
H score 35
1 unique sources, 1 articles

Summary

Hide ▲

The fake Codex download campaign is using sponsored search results, Google Sites lures, and ClickFix instructions to push macOS users into running malware. The fake portal impersonates an OpenAI Codex download page and steers victims into opening Terminal and pasting a command. That command decodes a URL, fetches a shell-script loader, and ends with a Mach-O payload. The delivery chain also overlaps with Atomic macOS Stealer (AMOS) techniques.

Related Happenings

AmnesiaStealer macOS infostealer distributed via ClickFix

Malware Activity
H score16 First: 14.08.2026 13:45 Last: 14.08.2026 13:45 Sources 1

About this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...

ClickFix AmnesiaStealer distribution campaign targeting mac users

Campaign
H score22 First: 14.08.2026 13:45 Last: 14.08.2026 13:45 Sources 1

About this happening: A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...

Latest development: 16.08.2026 18:07

Jamf described AmnesiaStealer's stream_module and remote_stream commands, which copy a victim's Chromium profile into a hidden headless browser and open WebSocket and Chrome DevTools Protocol channels through webSocketDebuggerUrl. The operator can issue navigation and mouse commands, receive live screencasts, and export or import cookies to operate online portals inside the victim's authenticated sessions on Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium.

ClickFix macOS Terminal-command lure campaign

Campaign
H score42 First: 07.08.2026 01:37 Last: 07.08.2026 01:37 Sources 1

About this happening: The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...

ClickFix Go-based macOS infostealer and crypto drainer

Malware Activity
H score29 First: 07.08.2026 01:37 Last: 07.08.2026 01:37 Sources 1

About this happening: A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...

PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS

Malware Activity
H score29 First: 21.07.2026 12:30 Last: 21.07.2026 12:30 Sources 1

About this happening: The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...

Timeline

  1. 24.08.2026 18:00 2 articles · 6h ago

    Fake Codex download campaign tricks macOS users with Google Sites and ClickFix

    Initial Disclosure

    Cato Networks said a fake Codex download campaign used sponsored search results to send macOS users to Google Sites pages impersonating an OpenAI Codex download portal, then used ClickFix instructions that told victims to open Terminal and paste a command that decoded a URL, fetched a shell-script loader, and ultimately delivered a Mach-O payload; the researchers observed active payload delivery only on macOS and noted overlap with Atomic macOS Stealer (AMOS) delivery techniques.

    Show sources