BRAD Duncan has analysed malware delivered through the active “Macfinger ClickFix” campaign, which uses injected scripts on legitimate websites to display fake CAPTCHA or bot-protection pages. Victims are instructed to paste commands into Terminal, causing a shell-script loader to download an architecture-specific Mach-O payload for either arm64 or x86_64 macOS systems.
In an infection observed on 24 September 2026 on macOS 27.0, the loader saved malware under `/Library/Caches/com.apple.securityd/com.apple.periodic` and established persistence through `/Users/[username]/Library/LaunchAgents/com.apple.softwareupdated.plist`, which ran a copy from the user’s cache directory.
The malware acted as an information stealer, requesting access to folders, applications, media and potentially passwords, including the macOS Keychain. Network evidence showed reporting to a command-and-control server at `95.163.153[.]80:8133`, including `/api/t` and `/api/credentials` requests, websocket traffic and HTTP data exfiltration. Duncan said the activity differs from the AMOS Stealer samples he previously examined, although he could not identify the malware definitively and noted he could still be wrong.
The report includes hashes, file locations and domains including `hollow-badger-moasfraum[.]life`, plus malware-hosting infrastructure at `45.131.215[.]56`; packet captures and malware samples are also available from the researcher’s analysis.