By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: New Atomic macOS Stealer Campaign Exploits ClickFix to Target Apple Users
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > New Atomic macOS Stealer Campaign Exploits ClickFix to Target Apple Users
Tech News

New Atomic macOS Stealer Campaign Exploits ClickFix to Target Apple Users

By Viral Trending Content 6 Min Read
Share
SHARE
New Atomic macOS Stealer Campaign

Cybersecurity researchers are alerting to a new malware campaign that employs the ClickFix social engineering tactic to trick users into downloading an information stealer malware known as Atomic macOS Stealer (AMOS) on Apple macOS systems.

The campaign, according to CloudSEK, has been found to leverage typosquat domains mimicking U.S.-based telecom provider Spectrum.

“macOS users are served a malicious shell script designed to steal system passwords and download an AMOS variant for further exploitation,” security researcher Koushik Pal said in a report published this week. “The script uses native macOS commands to harvest credentials, bypass security mechanisms, and execute malicious binaries.”

It’s believed that the activity is the work of Russian-speaking cybercriminals owing to the presence of Russian language comments in the malware’s source code.

Cybersecurity

The starting point of the attack is a web page that impersonates Spectrum (“panel-spectrum[.]net” or “spectrum-ticket[.]net”). Visitors to the sites in question are served a message that instructs them to complete a hCaptcha verification check to in order to “review the security” of their connection before proceeding further.

However, when the user clicks the “I am human” checkbox for evaluation, they are displayed an error message stating “CAPTCHA verification failed,” urging them to click a button to go ahead with an “Alternative Verification.”

Doing so causes a command to be copied to the users’ clipboard and the victim is shown a set of instructions depending on their operating system. While they are guided to run a PowerShell command on Windows by opening the Windows Run dialog, it’s substituted by a shell script that’s executed by launching the Terminal app on macOS.

The shell script, for its part, prompts users to enter their system password and downloads a next-stage payload, in this case, a known stealer called Atomic Stealer.

“Poorly implemented logic in the delivery sites, such as mismatched instructions across platforms, points to hastily assembled infrastructure,” Pal said.

“The delivery pages in question for this AMOS variant campaign contained inaccuracies in both its programming and front-end logic. For Linux user agents, a PowerShell command was copied. Furthermore, the instruction ‘Press & hold the Windows Key + R’ was displayed to both Windows and Mac users.”

The disclosure comes amid a surge in campaigns using the ClickFix tactic to deliver a wide range of malware families over the past year.

“Actors carrying out these targeted attacks typically utilize similar techniques, tools, and procedures (TTPs) to gain initial access,” Darktrace said. “These include spear phishing attacks, drive-by compromises, or exploiting trust in familiar online platforms, such as GitHub, to deliver malicious payloads.”

The links distributed using these vectors typically redirect the end user to a malicious URL that displays a fake CAPTCHA verification check and completes it in an attempt to deceive users into thinking that they are carrying out something innocuous, when, in reality, they are guided to execute malicious commands to fix a non-existent issue.

The end result of this effective social engineering method is that users end up compromising their own systems, effectively bypassing security controls.

In one April 2025 incident analyzed by Darktrace, unknown threat actors were found to utilize ClickFix as an attack vector to download nondescript payloads to burrow deeper into the target environment, conduct lateral movement, send system-related information to an external server via an HTTP POST request, and ultimately exfiltrate data.

“ClickFix baiting is a widely used tactic in which threat actors exploit human error to bypass security defenses,” Darktrace said. “By tricking endpoint users into performing seemingly harmless, everyday actions, attackers gain initial access to systems where they can access and exfiltrate sensitive data.”

Cybersecurity

Other ClickFix attacks have employed phony versions of other popular CAPTCHA services like Google reCAPTCHA and Cloudflare Turnstile for malware delivery under the guise of routine security checks.

These fake pages are “pixel-perfect copies” of their legitimate counterparts, sometimes even injected into real-but-hacked websites to trick unsuspecting users. Stealers such as Lumma and StealC, as well as full-fledged remote access trojans (RATs) like NetSupport RAT are some of the payloads distributed via bogus Turnstile pages.

“Modern internet users are inundated with spam checks, CAPTCHAs, and security prompts on websites, and they’ve been conditioned to click through these as quickly as possible,” SlashNext’s Daniel Kelley said. “Attackers exploit this ‘verification fatigue,’ knowing that many users will comply with whatever steps are presented if it looks routine.”

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Irish charity joins new EU project to save bees

iPadOS 18 vs. iPadOS 26: Key Differences and Upgrades

Asana warns MCP AI feature exposed customer data to other orgs

How to Watch Love Island in the US and Abroad

The challenges of High-Density AI for Data Centres

TAGGED: Atomic Stealer, ClickFix, CloudSEK, Cyber Security, Cybercrime, Cybersecurity, Darktrace, endpoint security, Information Stealer, Internet, MacOS, Malware, Remote Access Trojan, social engineering, Threat Intelligence, typosquatting
Share This Article
Facebook Twitter Copy Link
Previous Article XRP price forecast as Ripple USD (RLUSD) volume drops
Next Article Michaels is snapping up Joann Fabrics’ intellectual property and fan-favorite labels after the former cult-favorite retail darling’s bankruptcy disaster
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Airbus pledges higher dividends as it confirms financial guidance
Business
FBC: Firebreak PC Hotfix Improves Matchmaking, Fixes Connection Error Message
Gaming News
Deadliest places to go on holiday in 2025: Shock list ranks top tourist spots putting Brits and Americans at risk
World News
Irish charity joins new EU project to save bees
Tech News
Amazon’s AI boss reveals the make-or-break trait that decides whether you get hired—and it can’t be faked, rehearsed, or tested for
Business
Bitcoin Pepe presale nears major milestone ahead of Fed decision
Crypto
After What EA Did To BioWare, The Battlefield X Mass Effect Crossover Gives Me The Ick
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Airbus pledges higher dividends as it confirms financial guidance

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Airbus pledges higher dividends as it confirms financial guidance
June 18, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?