Microsoft tracked a macOS ClickFix operation across more than 250 front-end domains that uses server-side fingerprinting to hide the lure from crawlers and sandboxes while serving targeted Mac users a fake software download. The attack chain leads to Atomic Stealer (AMOS) and sometimes MacSync, and it still depends on the victim pasting and running an obfuscated Terminal command. #AtomicStealer #AMOS #MacSync #MicrosoftThreatIntelligence
Keypoints
- The campaign spans more than 250 front-end domains.
- Server-side fingerprinting hides the lure from crawlers and sandboxes.
- Selected Mac users receive a fake GitHub-style โDownload for macOSโ page.
- The malicious command fetches scripts and launches AMOS.
- Defenders should hunt the gate, shared infrastructure, and /curl/ paths.
Read More: https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html