Find notable cyber news and cases, enriched with sources, timelines, and signals.

PasteSwitch ClickFix malware delivery of MacSync, AMOS helper, and Amatera Stealer

Malware Activity
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

The PasteSwitch activity is using ClickFix ads to deliver MacSync, AMOS helper, and Amatera Stealer to Windows and macOS users, creating a high-risk path to credential theft and account compromise. A hijacked HBO Max Reddit account amplified the reach with 108 malicious ads over about 48 hours. The delivery chain relies on attacker-supplied commands pasted into trusted operating-system tools, helping the malware bypass some browser and security defenses.

Related Happenings

AmnesiaStealer macOS infostealer distributed via ClickFix

Malware Activity
H score16 First: 14.08.2026 13:45 Last: 14.08.2026 13:45 Sources 1

About this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...

Go-based macOS stealer with DRAIN wallet-draining routine

Malware Activity
H score29 First: 07.08.2026 21:29 Last: 07.08.2026 21:29 Sources 1

About this happening: A Go-based macOS stealer delivered through ClickFix-style attacks is stealing browser passwords, Apple iCloud Keychain data, and cached credentials while also...

ClickFix macOS Terminal-command lure campaign

Campaign
H score42 First: 07.08.2026 01:37 Last: 07.08.2026 01:37 Sources 1

About this happening: The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...

ClickFix Go-based macOS infostealer and crypto drainer

Malware Activity
H score29 First: 07.08.2026 01:37 Last: 07.08.2026 01:37 Sources 1

About this happening: A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...

DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS

Threat Actor Meta
H score28 First: 03.08.2026 23:01 Last: 03.08.2026 23:01 Sources 1

About this happening: DOUBLECUP is a Russian loader-as-a-service that packages ClickFix campaign tooling and has been active since early June 2026, according to SOCRadar. It supplie...

Timeline

  1. 14.09.2026 21:34 2 articles · 2h ago

    HBO Max Reddit account hijack drives ClickFix malware ads

    Initial Disclosure

    Researchers said the verified u/hbomax Reddit account for HBO Max was hijacked and used to run 108 malicious advertisements over about 48 hours, steering users to fake HBO Max download pages and ClickFix prompts that told them to paste commands into Windows Run, PowerShell, or macOS Terminal. The broader PasteSwitch campaign delivered MacSync, AMOS helper, and Amatera Stealer, and also pushed fake Ledger, Trezor Suite, and Exodus wallet apps plus AnimateClipper and ZigClipper.

    Show sources