A new ClickFix campaign was found attacking macOS.
A new ClickFix campaign has been detected, targeting a group of macOS users who search for a solution to the system.
Users of macOS have always had confidence in their strong security systems, but the problem has begun to be seen often. Over the past year, it can be seen that there has been news of malware and new hacking tactics that focus more on attacking macOS every day. And this is once again where macOS has been targeted.
According to a report by the Kriptokerrency exchange trading website, MEXC has mentioned the detection of a malware release campaign against a group of users of the macOS operating system by the ClickFix method, or the use of fake error alerts to trick them into running malware download and installation codes. This campaign was detected by the Defender Security Research Team from Microsoft in late 2025. (2025) The hackers will post troubleshooting that occurs during macOS use on channels such as Medium, Craft, and Squarespace to tempt victims who are searching for a solution to the problem that occurs during macOS use on search engines to get caught up with articles, prying instructions, tempting them to run dangerous code to install this malware.
After the victim has read the article, the article advises the victim to paste code on the Terminal application to download malware on the machine. It claims that the method is a solution to the macOS application that the user is searching for. After running the code, it will download these things.
Continuing Bird Malware (Loader)
Scripps.
Helper
These three tools serve to capture Sensitive Data, create persistence on the system for malware, and secretly send data back to hackers (Exfiltration) by malware that hackers may have used on this campaign. The research team says that hackers have been detected using both AMOS, Macsync, and SHub Stealer, which are malware specifically focused on attacking macOS users. This is the choice of one of the deceptive articles that hackers have trapped. These malware is effective in stealing all insidious data. These malware penetrates the account. iCloud and Telegram to search for private data in document and image file formats under 2MB. They also have the ability to steal keys used to recover popular wallet such as Exodus, Ledger, and Trezor, as well as to steal passwords saved on Chrome and Firefox web browsers.
For the malware operation, after the victim runs the code and installs the malware on the machine, the malware bounces a Dialog box asking the user to enter a System Password, purporting to install the Helper on the machine. If the victim enters it, it will immediately give the hacker complete access to the victim's system.
As for the additional malware capabilities of this campaign, the research team found that various elements of the malware have many capabilities. For example, the Loader will check the machine before running, and if the keyboard is found to be set to use the Russian language, the Loader will stop immediately, in some cases instead of malware stealing the data on a typical Krypto Currency wallet, it will switch the Krypto Currency wallet application on the victim's machine to a malware version, which will cover all three pockets mentioned above. In addition, it will be found to hide malware on the system like The hackers behind it also implemented several tools on macOS, curl and osascript, to run fileless malware on In-Memory Execution, making it difficult to detect later.
# Trending # Lemon 8 Howtoo # lemon 8 diary # macos # freedomhack


































































