<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/new-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer-tp3l5rbe7" -->

---
title: New macOS ClickFix attack silently mounts DMGs to push...
description: A new macOS ClickFix campaign uses fake CAPTCHA pages to trick users into running Terminal commands that silently download, mount, and execute malicious DMG...
canonical: https://daily.dev/posts/new-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer-tp3l5rbe7
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: New macOS ClickFix attack silently mounts DMGs to push infostealer | daily.dev
og:description: A new macOS ClickFix campaign uses fake CAPTCHA pages to trick users into running Terminal commands that silently download, mount, and execute malicious DMG...
og:url: https://daily.dev/posts/new-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer-tp3l5rbe7
og:image: https://api.daily.dev/og/posts/tp3l5rbE7.png
og:image:alt: New macOS ClickFix attack silently mounts DMGs to push infostealer
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# New macOS ClickFix attack silently mounts DMGs to push infostealer

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 4 min read · 0 upvotes · 0 comments

## Summary

A new macOS ClickFix campaign uses fake CAPTCHA pages to trick users into running Terminal commands that silently download, mount, and execute malicious DMG files. The payload is the Atomic macOS Stealer (AMOS), which harvests browser credentials, cryptocurrency wallet data, Apple Keychain files, messaging app data, and user documents. Unlike previous DMG-based attacks requiring manual user interaction, this campaign automates the entire infection chain via hdiutil and the macOS open command. The malware targets over a dozen Chromium and Firefox-based browsers, multiple crypto wallets, and even replaces legitimate Ledger Live and Trezor Suite installations with malicious versions. All stolen data is zipped and exfiltrated to attacker-controlled servers.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/new-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer>

## Similar posts on daily.dev

- [New macOS stealer campaign uses Script Editor in ClickFix attack](https://daily.dev/posts/new-macos-stealer-campaign-uses-script-editor-in-clickfix-attack-khhsvonhe) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#malware](https://daily.dev/tags/malware), [#mac](https://daily.dev/tags/mac)

[View this post on daily.dev](https://daily.dev/posts/new-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer-tp3l5rbe7)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"New macOS ClickFix attack silently mounts DMGs to push infostealer","url":"https://daily.dev/posts/new-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer-tp3l5rbe7","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/new-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer-tp3l5rbe7"},"datePublished":"2026-06-23T18:31:57.825Z","dateModified":"2026-06-23T18:32:43.610Z","description":"A new macOS ClickFix campaign uses fake CAPTCHA pages to trick users into running Terminal commands that silently download, mount, and execute malicious DMG...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/47acd12b72685ddb3e2881c6b6e8f751?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/47acd12b72685ddb3e2881c6b6e8f751?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/new-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer-tp3l5rbe7","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,malware,mac","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"New macOS ClickFix attack silently mounts DMGs to push infostealer"}]}
```

