www.infosecurity-magazine.com 8/24/2026, 3:07:16 PM · external

Fake Codex macOS lures via Google Sites to deliver hidden malware

Fake Codex macOS lures via Google Sites to deliver hidden malware
CyberSIXT Evidence Panel
Primary Source catonetworks.com

A fake Codex download campaign has exploited sponsored search results and Google Sites to deliver macOS malware, tricking users into executing it. Researchers from Cato Networks found that the campaign redirected users from queries like 'codex macos download' to impersonated download portals. The luring technique involved embedding malicious content within Google Sites, which masked the attack's true nature. The malware delivery relied on users pasting commands in Terminal that executed a shell script.

The attack demonstrated similarities to a previous macOS Malware campaign, emphasizing the need for comprehensive detection strategies.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT