Kurzfassung
Microsoft Threat Intelligence has tracked a macOS ClickFix campaign that tricks users into copying and running a malicious command in Terminal, ultimately installing infostealers like Atomic Stealer (AMOS) and MacSync. The lure appears as...
Wie es funktioniert
Microsoft Threat Intelligence has tracked a macOS ClickFix campaign that tricks users into copying and running a malicious command in Terminal, ultimately installing infostealers like Atomic Stealer (AMOS) and MacSync. The lure appears as...
Warnzeichen
- A webpage asks you to open Terminal and paste a command to "fix" a download, CAPTCHA, or update The site shows a forged "Verified Publisher" badge to look legitimate The page behaves differently depending on your browser/OS, a sign of cloaking What to do Never copy paste commands into Terminal from a website, even if the page looks official Keep macOS and your browser updated, and use endpoint protection that flags clipboard launched curl/bash chains If you already ran the command, change passwords stored in the browser, revoke active sessions, and consider
Was tun
- 1The lure appears as a fake CAPTCHA, software update, or download error page that asks you to "verify" by pasting a curl one liner into Terminal.
- 2Red flags A webpage asks you to open Terminal and paste a command to "fix" a download, CAPTCHA, or update The site shows a forged "Verified Publisher" badge to look legitimate The page behaves differently depending on your browser/OS, a sign of cloaking What to do Never copy paste commands into Terminal from a website, even if the page looks official Keep macOS and your browser updated, and use endpoint protection that flags clipboard launched curl/bash chains If you already ran the command, change passwords stored in the browser, revoke active sessions, and consider
Quelle
microsoft-security
Quelle geprueft vom Mythos Forensic Team
https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/FAQ
Ist Mac ClickFix scam hides behind fingerprinting gate to steal passwords ein reales Betrugsmuster?
Ja. Behandeln Sie Nachricht, Anruf oder Zahlungsaufforderung als verdaechtig, bis ein offizieller Kanal sie bestaetigt.
Was sind die ersten Warnzeichen?
A webpage asks you to open Terminal and paste a command to "fix" a download, CAPTCHA, or update The site shows a forged "Verified Publisher" badge to look legitimate The page behaves differently depending on your browser/OS, a sign of cloaking What to do Never copy paste commands into Terminal from a website, even if the page looks official Keep macOS and your browser updated, and use endpoint protection that flags clipboard launched curl/bash chains If you already ran the command, change passwords stored in the browser, revoke active sessions, and consider
Was sollte ich zuerst tun?
The lure appears as a fake CAPTCHA, software update, or download error page that asks you to "verify" by pasting a curl one liner into Terminal.; Red flags A webpage asks you to open Terminal and paste a command to "fix" a download, CAPTCHA, or update The site shows a forged "Verified Publisher" badge to look legitimate The page behaves differently depending on your browser/OS, a sign of cloaking What to do Never copy paste commands into Terminal from a website, even if the page looks official Keep macOS and your browser updated, and use endpoint protection that flags clipboard launched curl/bash chains If you already ran the command, change passwords stored in the browser, revoke active sessions, and consider
Kann LegalAudit meinen Fall pruefen?
Ja. Starten Sie den kostenlosen Chat und fuegen Sie Nachricht, Link, Absender oder Zahlungsdaten ein.