Security

ClickFix macOS Campaign Delivers Infostealers

3 min read

Summary

Microsoft has identified a new ClickFix-style campaign targeting macOS users with fake troubleshooting and utility instructions hosted on blogs and content platforms. Instead of downloading apps, victims are tricked into running Terminal commands that bypass typical macOS app checks and deploy infostealers such as Macsync, SHub Stealer, and AMOS.

Need help with Security?Talk to an Expert

Introduction

Microsoft is tracking an evolving ClickFix campaign that now targets macOS users through fake troubleshooting content and bogus utility installation instructions. This matters because the attack shifts away from traditional app downloads and instead abuses Terminal commands, helping attackers avoid some of the protections users expect from standard macOS application installs.

What’s new

Microsoft says threat actors are posting fake macOS advice on standalone websites, Medium, Craft, and similar user-driven platforms. The lures often claim to help with common issues such as freeing disk space or fixing system problems.

Key changes in this campaign include:

  • Users are instructed to paste Base64-encoded or obfuscated commands into Terminal
  • The commands retrieve remote content and launch script-based loaders
  • Attackers use native tools like curl, osascript, and shell interpreters
  • This method avoids the normal Gatekeeper-style checks applied to app bundles opened in Finder
  • Payloads observed include Macsync, SHub Stealer, and AMOS

Microsoft also identified three execution paths:

  • Loader install campaign
  • Script install campaign
  • Helper install campaign

Across these variants, the objective is consistent: collect credentials and sensitive files, establish persistence, and exfiltrate data.

Why it matters for IT admins

The malware goes beyond simple credential theft. According to Microsoft, these infostealers can collect:

  • Keychain entries
  • iCloud account data
  • Browser credentials
  • Telegram data
  • Media and documents
  • Cryptocurrency wallet data

Some variants also replace legitimate crypto wallet apps with trojanized versions, increasing the risk of financial theft.

For security teams, the bigger concern is user-driven execution. Because the victim manually runs commands in Terminal, attackers reduce dependence on malicious app packages and increase the chance of successful compromise.

Administrators and security teams should take the following steps:

  • Educate users not to paste commands into Terminal from blogs, forums, or troubleshooting pages
  • Monitor for suspicious use of curl, osascript, shell interpreters, and unexpected LaunchAgent or LaunchDaemon creation
  • Investigate staging paths such as /tmp/shub_<random ID> and unusual archive creation in /tmp
  • Review detections for data exfiltration, credential prompts, and persistence tied to fake update services
  • Prioritize protection for crypto-related apps and sensitive user data stores like Keychain

Bottom line

This ClickFix macOS campaign shows how social engineering is adapting to bypass traditional app-based defenses. For defenders, user awareness, endpoint monitoring, and detection of suspicious script execution are now critical to stopping these infostealer chains before data is stolen.

Need help with Security?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

macOS securityClickFixinfostealerMicrosoft Defendermalware

Related Posts

Security

Microsoft Digital Defense Report 2026: Key Security Insights

Microsoft's 2026 Digital Defense Report highlights how AI and growing system interconnectedness are reshaping both cyberattacks and defense strategies. The report emphasizes that organizations must secure AI, identities, data, and cloud environments together while improving signal correlation across tools to detect modern threats faster.

Security

Government Cyber Risk in 2026: Microsoft’s 5 Priorities

Microsoft says government agencies were the most targeted sector in 2026, accounting for 27% of observed cyber threat activity. The company urges public-sector leaders to focus on five resilience priorities, including faster response, AI security, bidirectional information sharing, and planning for incidents that spread across suppliers and essential services.

Security

Microsoft Ignite 2026 Security Guide: Key Sessions

Microsoft has published its security guide for Microsoft Ignite 2026, highlighting AI-first security themes, a dedicated Security Pre-Day, and technical sessions focused on securing identities, data, devices, clouds, and AI agents. For IT and security teams, the event offers an early look at Microsoft’s roadmap and practical guidance for building an AI-ready security strategy.

Security

CVE-2026-73570: Zimbra Mail Server Exploitation

Microsoft is tracking active exploitation of CVE-2026-73570, an unauthenticated command injection flaw affecting internet-facing Zimbra mail servers with the optional zimbra-snmp package installed and SNMP notifications enabled. The issue can lead to web shell deployment, privilege escalation, mailbox data theft, and persistent remote access, making immediate patching and configuration review critical for administrators.

Security

Phishing Abuses RMM Tools for Persistent Access

Microsoft security researchers observed phishing campaigns in July 2026 that used a legitimate MSP360 RMM installer disguised as meeting invites, PDF updates, and other lures to gain remote access. Attackers then deployed ConnectWise ScreenConnect for redundant persistence, highlighting the need for tighter controls on remote management tools and better detection of unapproved RMM activity.

Security

Azure DevOps Attack Path Exposed in New DART Report

Microsoft’s latest DART cyberattack report shows how a single compromised identity was used to access Azure DevOps, alter pipelines, and harvest Kubernetes credentials. The case highlights how tightly connected identity, DevOps, and cloud environments can let attackers move far beyond source code, making stronger identity and pipeline controls essential.