isc.sans.edu 23 Sept 2026, 00:46 UTC

ClickFix Campaign Uses Fake Bot Checks to Deploy macOS Stealer

ClickFix Campaign Uses Fake Bot Checks to Deploy macOS Stealer
CyberSIXT Evidence Panel Source marked as original reporting

A campaign dubbed “Macfinger ClickFix” is compromising legitimate websites with injected JavaScript that targets macOS users, according to SANS Internet Storm Centre researcher Brad Duncan. Observed on 21 and 22 September 2026, the activity uses ClickFix social engineering: visitors are shown a fake bot-protection page and prompted to follow verification instructions that can lead them to execute malicious commands.

The injected script also sends frequent HTTPS POST requests to a campaign-controlled domain, reporting user information and tracking interactions, including when a visitor abandons the page.

Duncan observed an initial Bash shell script downloaded from 45.150.33[.]128, followed by separate Mach-O executables for arm64 and x86_64 Macs. The files were identified by SHA-256 hashes 9d87b41c2b29ccbeac851b98f1a7dce4ab4781fec0cbc55fa6f93a6299a3d564, b68cdb1b46502fbce67ce3f8110682936d06afd2116af096e30abd4c8376b6dc and 1a3765e8cb0055ec31693b8f82ce9744106dee08368259661600b072c6805af4.

After execution, the infected host contacted 95.163.153[.]80 over TCP port 8133, including repeated requests to `/api/credentials`, as well as traffic involving `ipinfo[.]io`. Ransom-ISAC has described the final malware as a variant of Atomic macOS (AMOS) Stealer, but Duncan said it differs from AMOS activity he previously examined. He recommends using Microsoft’s ClickFix mitigation guidance; organisations can also use the published domains, addresses and hashes as detection indicators.

View full article

Article by CyberSIXT