HomeSecurityClickFix attacks spread MacSync infostealer

ClickFix attacks spread the MacSync infostealer

New ClickFix attacks target macOS users by spreading the MacSync infostealer via fake installations of artificial intelligence tools. These cyberattacks exploit social engineering to trick users into executing malicious commands in Terminal , bypassing Apple 's built-in security systems .

ClickFix attacks spread the MacSync infostealer

According to SophosJagadeesh Chandraiah, Tonmoy Jitu, Dmitry Samosseiko , and Matt Wixey, this method relies entirely on user interaction, usually in the form of copying and executing commands. This makes it particularly effective against users who do not understand the implications of executing unknown and encrypted commands.

Researchers have identified three different ClickFix campaigns acting as a distribution vehicle for the MacSync malware. It is not known whether the campaigns are the work of the same threat actor, but the use of ClickFix baits to spread the malware was also noted by Jamf Threat Labs in December 2025.

Three waves of attacks with ClickFix techniques

The first campaign was detected in November 2025 and used OpenAI ’s Atlas browser as bait . The attackers distributed the page through sponsored search results on Google , directing users to a fake Google Sites address . When users clicked the download button, they were prompted to open the Terminal application and paste a command that downloaded a shell script.

ClickFix attacks spread the MacSync infostealer

See also: ClickFix techniques used in new infostealer campaigns

In December 2025 , a second malvertising campaign exploited sponsored links associated with Google searches, such as “how to clean my Mac .” Users were directed to shared conversations on OpenAI ’s legitimate ChatGPT website, giving the impression that the links were safe. The ChatGPT conversations redirected victims to malicious GitHub -themed pages .

The third campaign, detected in February 2026, targeted Belgium, India , and parts of North and South America. This campaign distributed a new variant of MacSync that supports dynamic AppleScript payloads and in-memory execution to evade static analysis and bypass behavioral detections.

Technical details of the MacSync infostealer

The shell script that is launched after executing the Terminal is designed to communicate with a pre-defined server and retrieve the AppleScript infostealer payload. At the same time, it takes steps to remove traces of data theft. The MacSync stealer is equipped to collect a wide range of data from compromised computers, including credentials, files, keychain databases , and seed phrases from cryptocurrency wallets.

See also: Velvet Tempest: Distribution of DonutLoader and CastleRAT via ClickFix techniques

The new variant seen in the most recent campaign “ likely represents the malware developer’s adaptation of operating system and software security measures to maintain effectiveness ,” Sophos said . Therefore, improvements to ClickFix’s typical social engineering tactics are one way such campaigns may continue to evolve in the future.

In recent months, ClickFix campaigns have used legitimate platforms like Cloudflare Pages , Squarespace , and Tencent EdgeOne to host fake installation instructions for developer tools like Anthropic 's Claude Code . The URLs are distributed via malicious search engine ads.

See also: ClickFix attack distributes StealC malware to Windows systems

ClickFix campaign Windows Terminal Lumma Stealer malware attack

Researchers warn that macOS is no longer a lower-risk target than Windows, as infostealers are rapidly increasing. The evolution of ClickFix attacks shows that threat actors are constantly adapting to stay one step ahead of security tools, while exploiting the trust associated with ChatGPT to convince users to execute malicious commands.

To protect against such attacks, experts recommend that users avoid pasting unknown Terminal, verify the legitimacy of GitHub repositories , and use up-to-date antivirus programs that can detect MacSync. Organizations should block known ClickFix domains and deploy MDR (Managed Detection and Response) for better protection.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS