Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

August 5, 2026 2 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: macOS users
Incident: Deployment of AMOS infostealer via browser fingerprinting and social engineering.
Impact: Theft of browser credentials, authentication stores, cryptocurrency wallets, and sensitive files.
Attacker: Unidentified threat actors
Analysis: The campaign employs server-side validation to distinguish genuine macOS users from automated crawlers or analysts. By analyzing device telemetry and browser behavior, attackers only reveal malicious prompts to high-value targets. Once tricked, users execute obfuscated Terminal commands that deploy the Atomic Stealer (AMOS) infostealer.
Recommendations: Educate users never to paste unknown commands into the macOS Terminal; Implement DNS filtering to block suspicious domains combining ‘file’ with dictionary terms; Monitor for unauthorized shell process activity fetching remote scripts on macOS endpoints
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Latest Developments

Update — 2026-08-06 20:58 UTC

A social engineering campaign uses ‘ClickFix’ prompts to deploy a Go-based credential stealer on Mac devices. Loss of cryptocurrency funds and compromise of stored system and browser credentials. The attack employs a fake CAPTCHA prompt to trick users into pasting a malicious string into the macOS Terminal. This triggers a multi-stage download resulting in a Go-based stealer that targets the Apple Keychain and browser password stores. The malware specifically includes functionality to identify and drain cryptocurrency wallet balances.

Corroborating source: huntress.com

Leave a Reply

Your email address will not be published. Required fields are marked *