Fake Codex download campaign using Google Sites and ClickFix
Campaign
Summary
Hide ▲
Show ▼
The fake Codex download campaign is using sponsored search results, Google Sites lures, and ClickFix instructions to push macOS users into running malware. The fake portal impersonates an OpenAI Codex download page and steers victims into opening Terminal and pasting a command. That command decodes a URL, fetches a shell-script loader, and ends with a Mach-O payload. The delivery chain also overlaps with Atomic macOS Stealer (AMOS) techniques.
Related Happenings
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware Activity
H score16
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware ActivityAbout this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
ClickFix AmnesiaStealer distribution campaign targeting mac users
Campaign
H score22
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...
ClickFix AmnesiaStealer distribution campaign targeting mac users
CampaignAbout this happening: A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...
Latest development: 16.08.2026 18:07
Jamf described AmnesiaStealer's stream_module and remote_stream commands, which copy a victim's Chromium profile into a hidden headless browser and open WebSocket and Chrome DevTools Protocol channels through webSocketDebuggerUrl. The operator can issue navigation and mouse commands, receive live screencasts, and export or import cookies to operate online portals inside the victim's authenticated sessions on Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium.
ClickFix macOS Terminal-command lure campaign
Campaign
H score42
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
About this happening:
The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
ClickFix macOS Terminal-command lure campaign
CampaignAbout this happening: The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
ClickFix Go-based macOS infostealer and crypto drainer
Malware Activity
H score29
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
About this happening:
A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...
ClickFix Go-based macOS infostealer and crypto drainer
Malware ActivityAbout this happening: A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...
PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware Activity
H score29
First: 21.07.2026 12:30
Last: 21.07.2026 12:30
Sources 1
About this happening:
The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...
PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware ActivityAbout this happening: The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...
Timeline
-
24.08.2026 18:00 2 articles · 6h ago
Fake Codex download campaign tricks macOS users with Google Sites and ClickFix
Initial DisclosureCato Networks said a fake Codex download campaign used sponsored search results to send macOS users to Google Sites pages impersonating an OpenAI Codex download portal, then used ClickFix instructions that told victims to open Terminal and paste a command that decoded a URL, fetched a shell-script loader, and ultimately delivered a Mach-O payload; the researchers observed active payload delivery only on macOS and noted overlap with Atomic macOS Stealer (AMOS) delivery techniques.
Show sources
- Fake Codex Download Uses Google Sites to Deliver macOS Malware — www.infosecurity-magazine.com — 24.08.2026 18:00
- Fake Codex Download Uses Google Sites to Deliver macOS Malware — www.infosecurity-magazine.com — 24.08.2026 18:00