A fake Codex download campaign has exploited sponsored search results and Google Sites to deliver macOS malware, tricking users into executing it. Researchers from Cato Networks found that the campaign redirected users from queries like 'codex macos download' to impersonated download portals. The luring technique involved embedding malicious content within Google Sites, which masked the attack's true nature. The malware delivery relied on users pasting commands in Terminal that executed a shell script.
The attack demonstrated similarities to a previous macOS Malware campaign, emphasizing the need for comprehensive detection strategies.