Listen to the episode
TLDR
Microsoft Threat Intelligence has tracked a macOS ClickFix campaign that tricks users into copying and running a malicious command in Terminal, ultimately installing infostealers like Atomic Stealer (AMOS) and MacSync. The lure appears as...
How it works
Microsoft Threat Intelligence has tracked a macOS ClickFix campaign that tricks users into copying and running a malicious command in Terminal, ultimately installing infostealers like Atomic Stealer (AMOS) and MacSync. The lure appears as...
Red flags
- A webpage asks you to open Terminal and paste a command to "fix" a download, CAPTCHA, or update The site shows a forged "Verified Publisher" badge to look legitimate The page behaves differently depending on your browser/OS, a sign of cloaking What to do Never copy paste commands into Terminal from a website, even if the page looks official Keep macOS and your browser updated, and use endpoint protection that flags clipboard launched curl/bash chains If you already ran the command, change passwords stored in the browser, revoke active sessions, and consider
What to do
- 1The lure appears as a fake CAPTCHA, software update, or download error page that asks you to "verify" by pasting a curl one liner into Terminal.
- 2Red flags A webpage asks you to open Terminal and paste a command to "fix" a download, CAPTCHA, or update The site shows a forged "Verified Publisher" badge to look legitimate The page behaves differently depending on your browser/OS, a sign of cloaking What to do Never copy paste commands into Terminal from a website, even if the page looks official Keep macOS and your browser updated, and use endpoint protection that flags clipboard launched curl/bash chains If you already ran the command, change passwords stored in the browser, revoke active sessions, and consider
Source
microsoft-security
Source reviewed by Mythos Forensic Team
https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/FAQ
Is Mac ClickFix scam hides behind fingerprinting gate to steal passwords a real scam pattern?
Yes. Treat the message, call, or payment request as suspicious until you verify it through an official channel.
What are the first warning signs?
A webpage asks you to open Terminal and paste a command to "fix" a download, CAPTCHA, or update The site shows a forged "Verified Publisher" badge to look legitimate The page behaves differently depending on your browser/OS, a sign of cloaking What to do Never copy paste commands into Terminal from a website, even if the page looks official Keep macOS and your browser updated, and use endpoint protection that flags clipboard launched curl/bash chains If you already ran the command, change passwords stored in the browser, revoke active sessions, and consider
What should I do first?
The lure appears as a fake CAPTCHA, software update, or download error page that asks you to "verify" by pasting a curl one liner into Terminal.; Red flags A webpage asks you to open Terminal and paste a command to "fix" a download, CAPTCHA, or update The site shows a forged "Verified Publisher" badge to look legitimate The page behaves differently depending on your browser/OS, a sign of cloaking What to do Never copy paste commands into Terminal from a website, even if the page looks official Keep macOS and your browser updated, and use endpoint protection that flags clipboard launched curl/bash chains If you already ran the command, change passwords stored in the browser, revoke active sessions, and consider
Can LegalAudit check my case?
Yes. Start a free chat and paste the message, link, sender, or payment details for triage.