Published on August 5, 2026

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures-


Severity

Medium

Detail

Microsoft has identified a large-scale macOS ClickFix campaign using over 250 malicious domains to distribute Atomic Stealer (AMOS) and MacSync. The attackers use server-side fingerprinting to determine whether a visitor is a legitimate macOS user before displaying a fake software download page, helping them evade detection by security researchers and automated analysis tools.

How?

The attack begins when users visit a malicious website that secretly fingerprints their device using browser, system, and graphics information. If the visitor appears to be a real macOS user, the site displays a fake GitHub-style download page that instructs them to copy and run an obfuscated Terminal command.

Once executed, the command downloads additional scripts and installs Atomic Stealer (AMOS), which steals browser data, credentials, cryptocurrency wallets, authentication tokens, and sensitive files. To avoid detection, the malicious pages are only served to selected visitors, while crawlers and security tools receive harmless content or blank pages.

Conclusion

This campaign demonstrates how attackers are combining ClickFix social engineering with device fingerprinting to evade detection and target macOS users more effectively. Organizations should educate users to never execute Terminal commands from websites, monitor for suspicious Terminal activity, and use endpoint protections capable of detecting malicious scripts and unusual outbound network connections.

Source

https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html