macOS ClickFix Vulnerability Exploited to Deploy Atomic Stealer
Key Takeaways A new “ClickFix” social engineering campaign is actively targeting macOS users. The attack deceives users into executing malicious Terminal commands under the guise of...
Key Takeaways
- A new “ClickFix” social engineering campaign is actively targeting macOS users.
- The attack deceives users into executing malicious Terminal commands under the guise of CAPTCHA verification or system updates.
- This campaign deploys Atomic macOS Stealer (AMOS), a sophisticated infostealer.
- AMOS can exfiltrate sensitive data, including browser credentials, financial information, cryptocurrency wallet data, and messaging app contents.
- The attack bypasses traditional security measures by manipulating the victim into self-infecting, highlighting the importance of user vigilance.
macOS users are currently under attack by a sophisticated social engineering campaign dubbed “ClickFix,” which leverages fake verification prompts to trick victims into installing the Atomic macOS Stealer (AMOS) malware. This campaign represents an expansion of ClickFix lures, which previously focused primarily on Windows users, according to Kaspersky said in a report.
Table Of Content
Instead of exploiting software vulnerabilities, the ClickFix attack weaponizes user trust. It manipulates individuals into willingly executing harmful commands in their Terminal, believing they are performing routine security checks or system fixes. This deceptive tactic allows the malware to bypass many built-in macOS security features.
Once a victim runs the provided command, it initiates the download and execution of a concealed disk image containing AMOS. This potent information stealer is designed for extensive data exfiltration, posing a significant threat of account compromise and financial theft.
ClickFix Delivers Atomic Stealer
The attack typically begins when a user visits a compromised or malicious website. The site then displays a fabricated error message, a verification request, or a browser update notification. To “resolve” the issue, the site instructs the user to copy a specific line of text, open the macOS Terminal application, paste the text, and execute it.
This social engineering technique is particularly insidious as it presents a dangerous action as a necessary step to continue browsing or to fix a perceived problem. This approach mirrors other recent macOS threats, such as a macOS Script Editor campaign, where attackers similarly aimed to make malicious actions appear legitimate.
Upon execution, the command stealthily downloads a malicious Disk Image (DMG) file. This file is saved in a temporary macOS folder under a randomized name, making it harder to detect. The script then mounts this disk image without displaying it in Finder or placing an icon on the desktop, further obscuring its presence. Subsequently, it automatically locates and launches an application or installer package contained within the DMG.
In a further attempt to gain deeper access, Atomic Stealer may display a fake macOS authentication dialog. If a user enters their password into this deceptive prompt, the malware can obtain elevated privileges, granting it access to even more sensitive system data while appearing to the user as a standard system request.
The efficacy of this method lies in its ability to trick the user into performing the critical steps of the attack. By convincing the user to approve the command, download the installer, and potentially provide an administrator password, attackers circumvent direct security bypasses, leveraging the victim’s own actions against them.
Passwords, Wallets, and Data at Risk
Once successfully installed, Atomic Stealer initiates a broad search for sensitive information across the compromised macOS system. It targets a wide array of web browsers, including Chromium-based browsers like Chrome, Edge, Brave, Opera, Arc, Vivaldi, CocCoc, and Yandex, as well as Firefox-based browsers.
The malware is capable of extracting various types of data from these browsers, including saved login credentials, browser cookies, autofill data, payment card details, and comprehensive browser profile information stored on the Mac.
Beyond browser data, AMOS also targets Safari cookies, Apple Notes, and critically, passwords stored in Apple Keychain. It also looks for personal files with common extensions such as PDF, TXT, and RTF. Furthermore, the stealer actively seeks data from popular desktop messaging applications like Telegram and Discord. The theft of this information could lead to not only personal data compromise but also enable attackers to impersonate victims in future scams.
Cryptocurrency holders face an elevated risk. AMOS is programmed to identify and collect data from numerous desktop wallet applications, including Exodus, Electrum, Atomic Wallet, Wasabi Wallet, Bitcoin Core, Litecoin Core, DashCore, Guarda, Binance Wallet, Dogecoin Wallet, and Tonkeeper. Additionally, it targets information from over 200 crypto-related browser extensions.
The campaign extends its reach by attempting to replace legitimate cryptocurrency applications, such as Ledger Wallet and Trezor Suite, with malicious versions. This tactic creates another avenue for attackers to steal digital assets, echoing previous reports of fraudulent Ledger apps targeting Mac users.
All collected sensitive information is then compressed into a ZIP archive and exfiltrated to the attackers’ command-and-control servers. The stolen passwords, cookies, and wallet data can be immediately used for unauthorized account access, direct fund theft, or to facilitate further social engineering attacks against the victim’s contacts or professional networks.
What You Should Do
- Never Execute Unsolicited Terminal Commands: Under no circumstances should you copy and paste commands into your Terminal application if a website or an unexpected prompt instructs you to do so, regardless of the reason (e.g., CAPTCHA verification, error fix, content unlock). Legitimate websites do not require this action.
- Be Skeptical of Password Prompts: Exercise extreme caution with any unexpected macOS authentication dialogs. Always verify the legitimacy of such prompts and ensure they correspond to an action you initiated.
- Keep macOS Updated: Install all available macOS updates promptly. While this attack is social engineering-based, keeping your system patched ensures you have the latest security protections against other potential threats.
- Use a Reputable Antivirus Solution: Deploy and maintain a robust antivirus or anti-malware solution specifically designed for macOS to detect and block malicious software like Atomic Stealer.
- Enable Multi-Factor Authentication (MFA): Activate MFA on all critical online accounts, especially for email, banking, and cryptocurrency services. This adds an essential layer of security, even if your password is stolen.
- Regularly Back Up Your Data: Maintain regular backups of important files to an external or cloud storage solution.
- Be Wary of Suspicious Websites and Downloads: Avoid visiting untrusted websites, clicking on suspicious links, or downloading software from unofficial sources.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.