www.microsoft.com 8/5/2026, 5:06:32 PM · external

macOS ClickFix trick spreads MacSync and Atomic Stealer malware

macOS ClickFix trick spreads MacSync and Atomic Stealer malware
CyberSIXT Evidence Panel Source marked as original reporting

THE Microsoft Threat Intelligence team has analyzed a macOS ClickFix campaign that distributes information-stealing malware, including MacSync and Atomic Stealer (AMOS), using sophisticated server-side methods. The campaign evolved from openly serving malicious commands to employing a fingerprinting gate that restricts visibility to genuine macOS browser environments, thereby evading detection mechanisms. Key points include the following:

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline