macos malware5 articles
Fake OpenAI Codex Ads Are Serving Mac Malware Via Terminal Commands
Cybercriminals are running a malware campaign targeting Mac developers by placing fake sponsored Google ads for OpenAI Codex, directing victims to convincing but fraudulent download pages. Instead of providing an installer, the sites instruct users to run a terminal command that covertly triggers a multi-stage malware infection — a tactic known as "ClickFix" — ultimately deploying what appears to be the AMOS infostealer. A similar fake page impersonating Anthropic's Claude Code was also discovered sharing the same infrastructure, suggesting a broader campaign against developers seeking AI coding tools.
AmnesiaStealer: The macOS Malware That Watches You Browse in Real Time
is a newly discovered Rust-based macOS malware distributed via a fake GitHub page using ClickFix-style social engineering, tricking victims into running a malicious Terminal command. Once installed, it harvests sensitive data including browser databases, keychains, Apple Notes, and documents, while also attempting to bypass macOS's TCC framework to gain broader access. A particularly notable feature is its remote-control "stream module," which uses the Chrome DevTools Protocol to launch a hidden browser session, giving attackers live, interactive control over the victim's browsing activity.
ClickFix Malware Can Slowly Bleed Your Crypto Wallet Dry
ClickFix-style attacks are being used to deliver a Go-based macOS malware that steals browser passwords, Apple Keychain data, and cryptocurrency wallet contents, with the ability to gradually drain funds across multiple cryptocurrencies including Bitcoin, Ethereum, and Monero. The attack tricks victims into pasting a command into Terminal, which profiles the system, downloads a compatible payload, and uses a fake error prompt to harvest system credentials. The malicious infrastructure is linked to Aeza Group, a Russian bulletproof hosting provider sanctioned by the US, UK, and Australia.
North Korea's Contagious Interview Campaign Goes Full ClickFix With Blockchain C2
North Korea-linked threat actors have launched a sophisticated macOS malvertising campaign, dubbed a new iteration of "Contagious Interview," that redirects users to fake websites displaying a convincing full-screen fake software update to trick them into running malicious Terminal commands via the ClickFix technique. The malware uses "EtherHiding" — embedding C2 server addresses in Ethereum smart contracts — to resist takedowns, ultimately delivering an information stealer targeting 157 cryptocurrency wallets and a malicious Chrome extension designed to drain victims' funds. Notably, this campaign departs from the group's typical fake job interview lures, instead targeting ordinary web searches, suggesting North Korean operators are broadening their attack vectors beyond developer recruitment scenarios.
Roundup: Iranian Spooks Track US Troops Via Ad Data, macOS Malware Plays Dead, and a Textile Firm Goes Bust After Six Weeks of Ransomware Hell
This SecurityWeek roundup covers a broad range of cybersecurity developments, including a German manufacturer filing for bankruptcy after a six-week production shutdown caused by a cyberattack, and Iranian threat actors exploiting advertising and cellular roaming data to track US military personnel's smartphones. Other highlights include the discovery of CrashStealer, a new macOS information-stealing malware that disguises itself as a legitimate crash reporter, and a joint CISA guide providing organisations with a framework for establishing Coordinated Vulnerability Disclosure programs. Additional stories touch on supply chain breaches affecting Lidl customers, ransomware targeting an Asian IT firm, and a cybercrime group claiming to have stolen over 1TB of data from naval defence manufacturer Thyssenkrupp Marine Systems.