A trap the victim springs themselves
Companies often have no idea this now happens on Macs too. Researchers described a new wave of so-called ClickFix attacks aimed at macOS users, and it rests on one thing, a false sense of safety. A spoofed page shows a prompt like "verify you are not a robot" or "fix your display", along with instructions: copy this command and paste it into Terminal. The victim does it themselves, which triggers a download of Go-based malware built for their specific CPU architecture.
The payload then steals cryptocurrency, browser-stored passwords, iCloud Keychain data, and cached credentials. Try to look at it through the attacker's eyes. They do not need to break any defense, they only need to convince the user to bypass it for them. And to stay hidden, the operation runs across more than 250 front-end domains that fingerprint the visitor first and show the malicious page only to selected Mac users. Crawlers and sandboxes get harmless content. A Russian loader-as-a-service called DOUBLECUP works in the same spirit, using ClickFix to hide malware inside PNG images cached by the browser.
What to do:
- Teach people a clear rule. No legitimate site asks you to paste commands into Terminal or PowerShell. That is almost always an attack.
- macOS is not immune. Put endpoint protection and detection on Macs too, not just on Windows.
- On endpoints, watch for a shell launched from the browser and payloads fetched by CPU architecture. That is this campaign's pattern.