Mac users are being targeted by a ClickFix campaign that turns a fake verification prompt into a path for malware installation.
Victims are persuaded to copy a command from a web page, open Terminal, paste it, and run it, believing they are completing a routine CAPTCHA check.
The attack does not rely on a software flaw. Instead, it abuses trust and familiar security prompts, making the victim carry out the harmful action themselves.
Once the command runs, it downloads and launches a hidden disk image containing Atomic macOS Stealer, also known as AMOS.
Kaspersky said in a report shared with Cyber Security News (CSN) that the activity shows ClickFix lures are expanding beyond their earlier focus on Windows users.
Researchers noted that the campaign uses a fake CAPTCHA page to guide Apple device owners into launching the infection chain.
.webp)
The impact can extend far beyond a single browser session. Atomic Stealer is built to collect passwords, payment details, browser cookies, personal files, wallet information, and data from messaging applications, creating opportunities for account takeover and cryptocurrency theft.
ClickFix Delivers Atomic Stealer
In a typical attack, a compromised or fraudulent site displays an error, verification message, or browser update notice. It then tells visitors to copy text, open Terminal, and execute it, presenting the steps as a necessary fix rather than a dangerous command.
This social-engineering approach mirrors techniques seen in a recent macOS Script Editor campaign, where attackers also sought to avoid suspicion.
.webp)
After execution, the command retrieves a malicious DMG file and saves it in macOS’s temporary folder under a random name.
The script mounts the disk image without displaying it in Finder or placing an icon on the desktop, then searches for an application or installer package and starts it automatically.
Atomic Stealer may then show a counterfeit macOS authentication dialog to obtain elevated access.
A password entered into that prompt can give the malware access to more valuable data, while making the request appear like a normal system action to an unsuspecting user.
This method is especially effective because it places the most important action in the victim’s hands.
The attacker does not need to bypass protections directly when a user has already approved the command, downloaded the installer, and potentially supplied an administrator password.
Passwords, Wallets and Data
Once installed, Atomic Stealer searches Chromium-based browsers, including Chrome, Edge, Brave, Opera, Arc, Vivaldi, CocCoc, and Yandex, along with Firefox-based browsers.
It can collect saved credentials, cookies, autofill data, payment-card details, and browser profile information stored on the Mac.
The malware also targets Safari cookies, Apple Notes, Apple Keychain passwords, and files with PDF, TXT, and RTF extensions.
It seeks data from Telegram and Discord desktop apps, meaning the theft may expose both personal information and communications that could help attackers impersonate victims.
.webp)
Cryptocurrency users face an additional risk. AMOS looks for desktop wallet applications such as Exodus, Electrum, Atomic Wallet, Wasabi Wallet, Bitcoin Core, Litecoin Core, DashCore, Guarda, Binance Wallet, Dogecoin Wallet, and Tonkeeper, while also gathering information from more than 200 crypto-related browser extensions.
The campaign can replace legitimate Ledger Wallet and Trezor Suite applications with malicious versions, adding another route to steal digital assets.
Similar threats have increasingly targeted Apple users through fake wallet software, as shown in reporting on fraudulent Ledger apps targeting Mac users.
Collected information is placed into a ZIP archive and sent to the attackers’ server. Stolen passwords, cookies, and wallet data can be used to access accounts, steal funds, or support follow-on scams against the victim’s contacts and workplace.
Users should never paste commands into Terminal because a website asks them to pass a check, confirm an identity, or reveal content.
Legitimate websites do not require visitors to run Terminal commands, and users should reject unexpected password prompts, install macOS updates promptly, and trust operating-system warnings over website instructions.
The broader lesson is that familiar-looking prompts are not proof of safety. Awareness of ClickFix lures used against users can help Mac owners pause before running any command that they did not create or fully understand.
Building Resilience Against Phishing & Malware and Analyze it in a safe environment – Power your SOC with ANY.RUN
The post macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets appeared first on Cyber Security News.
