A new macOS ClickFix campaign uses fake CAPTCHA pages to trick users into running Terminal commands that silently download, mount, and execute malicious DMG files. The payload is the Atomic macOS Stealer (AMOS), which harvests browser credentials, cryptocurrency wallet data, Apple Keychain files, messaging app data, and user documents. Unlike previous DMG-based attacks requiring manual user interaction, this campaign automates the entire infection chain via hdiutil and the macOS open command. The malware targets over a dozen Chromium and Firefox-based browsers, multiple crypto wallets, and even replaces legitimate Ledger Live and Trezor Suite installations with malicious versions. All stolen data is zipped and exfiltrated to attacker-controlled servers.

4m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:
283 Impressions