PasteSwitch ClickFix malware delivery of MacSync, AMOS helper, and Amatera Stealer
Malware Activity
Summary
Hide ▲
Show ▼
The PasteSwitch activity is using ClickFix ads to deliver MacSync, AMOS helper, and Amatera Stealer to Windows and macOS users, creating a high-risk path to credential theft and account compromise. A hijacked HBO Max Reddit account amplified the reach with 108 malicious ads over about 48 hours. The delivery chain relies on attacker-supplied commands pasted into trusted operating-system tools, helping the malware bypass some browser and security defenses.
Related Happenings
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware Activity
H score16
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware ActivityAbout this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
Go-based macOS stealer with DRAIN wallet-draining routine
Malware Activity
H score29
First: 07.08.2026 21:29
Last: 07.08.2026 21:29
Sources 1
About this happening:
A Go-based macOS stealer delivered through ClickFix-style attacks is stealing browser passwords, Apple iCloud Keychain data, and cached credentials while also...
Go-based macOS stealer with DRAIN wallet-draining routine
Malware ActivityAbout this happening: A Go-based macOS stealer delivered through ClickFix-style attacks is stealing browser passwords, Apple iCloud Keychain data, and cached credentials while also...
ClickFix macOS Terminal-command lure campaign
Campaign
H score42
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
About this happening:
The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
ClickFix macOS Terminal-command lure campaign
CampaignAbout this happening: The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
ClickFix Go-based macOS infostealer and crypto drainer
Malware Activity
H score29
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
About this happening:
A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...
ClickFix Go-based macOS infostealer and crypto drainer
Malware ActivityAbout this happening: A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...
DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS
Threat Actor Meta
H score28
First: 03.08.2026 23:01
Last: 03.08.2026 23:01
Sources 1
About this happening:
DOUBLECUP is a Russian loader-as-a-service that packages ClickFix campaign tooling and has been active since early June 2026, according to SOCRadar. It supplie...
DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS
Threat Actor MetaAbout this happening: DOUBLECUP is a Russian loader-as-a-service that packages ClickFix campaign tooling and has been active since early June 2026, according to SOCRadar. It supplie...
Timeline
-
14.09.2026 21:34 2 articles · 2h ago
HBO Max Reddit account hijack drives ClickFix malware ads
Initial DisclosureResearchers said the verified u/hbomax Reddit account for HBO Max was hijacked and used to run 108 malicious advertisements over about 48 hours, steering users to fake HBO Max download pages and ClickFix prompts that told them to paste commands into Windows Run, PowerShell, or macOS Terminal. The broader PasteSwitch campaign delivered MacSync, AMOS helper, and Amatera Stealer, and also pushed fake Ledger, Trezor Suite, and Exodus wallet apps plus AnimateClipper and ZigClipper.
Show sources
- Hackers hijack HBO Max Reddit account to push malware in ClickFix ads — www.bleepingcomputer.com — 14.09.2026 21:34
- Hackers hijack HBO Max Reddit account to push malware in ClickFix ads — www.bleepingcomputer.com — 14.09.2026 21:34