Scam Radar

How can you recognize Mac ClickFix scam hides behind fingerprinting gate to steal passwords?

Published

Listen to the episode

TLDR

Microsoft Threat Intelligence has tracked a macOS ClickFix campaign that tricks users into copying and running a malicious command in Terminal, ultimately installing infostealers like Atomic Stealer (AMOS) and MacSync. The lure appears as...

How it works

Microsoft Threat Intelligence has tracked a macOS ClickFix campaign that tricks users into copying and running a malicious command in Terminal, ultimately installing infostealers like Atomic Stealer (AMOS) and MacSync. The lure appears as...

Red flags

  • A webpage asks you to open Terminal and paste a command to "fix" a download, CAPTCHA, or update The site shows a forged "Verified Publisher" badge to look legitimate The page behaves differently depending on your browser/OS, a sign of cloaking What to do Never copy paste commands into Terminal from a website, even if the page looks official Keep macOS and your browser updated, and use endpoint protection that flags clipboard launched curl/bash chains If you already ran the command, change passwords stored in the browser, revoke active sessions, and consider

What to do

  1. 1The lure appears as a fake CAPTCHA, software update, or download error page that asks you to "verify" by pasting a curl one liner into Terminal.
  2. 2Red flags A webpage asks you to open Terminal and paste a command to "fix" a download, CAPTCHA, or update The site shows a forged "Verified Publisher" badge to look legitimate The page behaves differently depending on your browser/OS, a sign of cloaking What to do Never copy paste commands into Terminal from a website, even if the page looks official Keep macOS and your browser updated, and use endpoint protection that flags clipboard launched curl/bash chains If you already ran the command, change passwords stored in the browser, revoke active sessions, and consider

Source

FAQ

Is Mac ClickFix scam hides behind fingerprinting gate to steal passwords a real scam pattern?

Yes. Treat the message, call, or payment request as suspicious until you verify it through an official channel.

What are the first warning signs?

A webpage asks you to open Terminal and paste a command to "fix" a download, CAPTCHA, or update The site shows a forged "Verified Publisher" badge to look legitimate The page behaves differently depending on your browser/OS, a sign of cloaking What to do Never copy paste commands into Terminal from a website, even if the page looks official Keep macOS and your browser updated, and use endpoint protection that flags clipboard launched curl/bash chains If you already ran the command, change passwords stored in the browser, revoke active sessions, and consider

What should I do first?

The lure appears as a fake CAPTCHA, software update, or download error page that asks you to "verify" by pasting a curl one liner into Terminal.; Red flags A webpage asks you to open Terminal and paste a command to "fix" a download, CAPTCHA, or update The site shows a forged "Verified Publisher" badge to look legitimate The page behaves differently depending on your browser/OS, a sign of cloaking What to do Never copy paste commands into Terminal from a website, even if the page looks official Keep macOS and your browser updated, and use endpoint protection that flags clipboard launched curl/bash chains If you already ran the command, change passwords stored in the browser, revoke active sessions, and consider

Can LegalAudit check my case?

Yes. Start a free chat and paste the message, link, sender, or payment details for triage.