Find notable cyber news and cases, enriched with sources, timelines, and signals.

ClickFix macOS Terminal-command lure campaign

Campaign
First reported
Last updated
Happening score
H score 42
1 unique sources, 1 articles

Summary

Hide ▲

The ClickFix campaign is pushing macOS users to run a Terminal command, creating a live path to credential theft and crypto diversion. The lure arrives through email-delivered links that open a page with instructions to execute the command. The resulting chain loads a Bash profiler/loader and a Mach-O payload tailored to the victim system. The same activity is tied to theft of browser passwords, Apple Keychain data, cached credentials, and cryptocurrency transactions.

Related Happenings

ClickFix Go-based macOS infostealer and crypto drainer

Malware Activity
H score29 First: 07.08.2026 01:37 Last: 07.08.2026 01:37 Sources 1

How related: A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials.

About this happening: A Go-based malware delivered through ClickFix now targets macOS users and steals cryptocurrency assets plus saved credentials, creating immediate wallet-drain and...

Fake Bank of America phishing remote-control campaign

Campaign
H score32 First: 05.08.2026 11:00 Last: 05.08.2026 11:00 Sources 1

About this happening: The fake Bank of America phishing campaign is delivering a multi-stage download chain that can install ScreenConnect and give attackers remote control of victim sy...

DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity

Malware Activity
H score22 First: 03.08.2026 23:01 Last: 03.08.2026 23:01 Sources 1

About this happening: DOUBLECUP is a Russian loader-as-a-service active since early June 2026 that uses ClickFix lures and browser-cached steganographic PNGs to deliver CountLoade...

PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS

Malware Activity
H score29 First: 21.07.2026 12:30 Last: 21.07.2026 12:30 Sources 1

About this happening: The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...

Famous Chollima ClickFake Interview recruitment scam campaign

Campaign
H score34 First: 21.07.2026 12:30 Last: 21.07.2026 12:30 Sources 1

About this happening: A Famous Chollima recruitment scam is targeting Web3 and cryptocurrency professionals with fake job interviews and malicious assessment portals that deliver remote a...

Timeline

  1. 07.08.2026 01:37 2 articles · 18h ago

    ClickFix delivers a macOS infostealer that steals Apple Keychain data and crypto assets

    Technical Analysis Update

    A Go-based malware delivered through ClickFix lures against macOS users uses an email link to a page that instructs the victim to run a command in Terminal, then drops a Bash profiler and loader plus a matching Mach-O payload. The malware steals browser-stored passwords, Apple Keychain data, cached credentials, and cryptocurrency assets, can alter transactions before signing to divert funds, and uses com.apple.verified together with a removed com.apple.quarantine attribute to evade Gatekeeper. It also communicates with shared IP addresses in AS 210644 linked to the Aeza Group.

    Show sources