Hackers are using the ClickFix attack method, which combines fake human verification prompts with malware, in an attempt to trick users into executing Terminal commands that bypass macOS. The tactic disguises the delivery of malware as a standard human verification step.
See also: Velvet Tempest: Distribution of DonutLoader and CastleRAT via ClickFix techniques

Victims are instructed to open tools like Terminal or a command prompt and paste a command to complete verification. Running the command installs malware on the system. Data that can be stolen includes passwords, browser information, and cryptocurrency wallets.
This new threat poses a serious risk to Mac users by exploiting their trust in seemingly innocent verification processes. Attackers use fake pages or pop-ups that ask users to confirm they are human, which is common with many online services. However, instead of completing a simple verification, users are tricked into executing commands that bypass macOS’s built-in security measures.
This process may seem innocent, but the consequences are serious. Once the command is executed, malware can be installed without anyone noticing, allowing hackers to gain access to sensitive information. Passwords, browsing information, and cryptocurrency wallets are just some of the data that can be stolen, putting users’ security and privacy at risk.
See also: Microsoft: New ClickFix campaign distributes Lumma Stealer

Mac users should be extra cautious when prompted to execute commands in Terminal, especially when those commands come from unknown or untrusted sources. It's important to verify the authenticity of verification requests and avoid executing commands that they don't fully understand. Keeping security software up to date and using reputable malware detection tools can also help protect against such threats.
The security community is warning that ClickFix-type attacks may become more common as hackers continue to find new ways to bypass security measures. It is critical for users to stay up to date on the latest threats and take proactive steps to protect their systems. Awareness and education are the best weapons against malicious attacks.
See also: Pastebin comments promote ClickFix JavaScript attack

In summary, ClickFix is a new and dangerous threat to Mac users, exploiting their trust in verification processes. Caution and vigilance are essential to avoid such attacks and protect personal data.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
