discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

New macOS ClickFix attack silently mounts DMGs to push infostealer

A new macOS ClickFix campaign uses Terminal commands to download and launch info-stealing malware from malicious DMG files. The campaign infects Mac devices with the Atomic macOS Stealer, which steals browser credentials and cryptocurrency wallet data.

By Lawrence Abrams·Jun 23·bleepingcomputer.com·2 min read

Intelligence analysis by Llama 3.3 70B

New macOS ClickFix attack silently mounts DMGs to push infostealer
Image: bleepingcomputer.com

The ClickFix attack begins with a fake CAPTCHA page that tricks users into executing a malicious Terminal command, which downloads and mounts a DMG file containing the malware.

Why it matters

This campaign highlights the growing threat of social engineering attacks on macOS devices, which can lead to significant data breaches and financial losses. The use of ClickFix attacks to distribute malware is a concerning trend that users and security teams should be aware of.

Imagine you're on a website and it asks you to do something to prove you're human. But instead of just checking a box, it asks you to type a special command into your computer. That's what's happening in this attack. The bad guys are tricking people into typing a command that lets them steal sensitive information, like passwords and cryptocurrency.

Analysis

The Evolution of ClickFix Attacks

The ClickFix technique has been used by threat actors to distribute malware, and its popularity has grown in the past year. This campaign combines social engineering with the use of Terminal commands to silently download and launch malware, making it a more sophisticated and stealthy attack.

The use of fake CAPTCHA pages to trick users into executing malicious commands is a common tactic used by attackers. This campaign takes it a step further by using the Terminal command to download and mount a DMG file, which contains the malware. This approach allows the attackers to bypass traditional security measures and infect the device without the user's knowledge.

The Atomic macOS Stealer

The malware used in this campaign is the Atomic macOS Stealer, which is a highly sophisticated infostealer that can steal a wide range of sensitive data, including browser credentials, cryptocurrency wallet data, and user documents. The stealer is designed to target multiple browsers, including Chromium-based and Firefox-derived browsers, and can steal various types of data, including cookies, login databases, and autofill information.

The stealer also targets cryptocurrency wallet data, including Exodus, Electrum, and Atomic Wallet, and can replace legitimate installations of Ledger Live and Trezor Suite with malicious versions. This suggests that the attackers are highly motivated to steal cryptocurrency and other sensitive data, and are willing to use sophisticated tactics to achieve their goals.

Mitigation and Prevention

To mitigate the risk of ClickFix attacks, users should be cautious when websites instruct them to open Terminal and execute commands. It is especially important to be wary of commands that claim to be part of CAPTCHA verifications, browser fixes, or other troubleshooting steps. Users should never execute a command that they do not fully understand, and should always verify the authenticity of the command before running it.

Security teams should also be aware of the growing threat of ClickFix attacks and take steps to educate users about the risks. This can include providing training on how to identify and avoid social engineering attacks, as well as implementing security measures to detect and prevent malware infections.

Key points

  • ClickFix attack uses Terminal commands to download and launch malware
  • Malware steals browser credentials and cryptocurrency wallet data
  • Attack begins with fake CAPTCHA page that tricks users into executing malicious command
The Upside

As security teams become more aware of the ClickFix threat, they can take steps to educate users and implement measures to prevent these types of attacks. By being cautious and vigilant, users can reduce the risk of falling victim to these attacks and protect their sensitive data.

The Downside

The growing sophistication of ClickFix attacks and the use of highly effective malware like the Atomic macOS Stealer suggest that these types of attacks will continue to be a significant threat to macOS users. If left unchecked, these attacks could lead to significant data breaches and financial losses, highlighting the need for increased awareness and vigilance among users and security teams.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritymacosmalwareclickfixinfostealer

Author

Lawrence Abrams

Intelligence analysis by

Llama 3.3 70B

Published

Jun 23, 2026

Source

bleepingcomputer.com

Share

Topics

securitymacosmalwareclickfixinfostealer

Related

More from this desk

Aug 14·bleepingcomputer.com

Hackers Arrested Over €30M Bank Fraud Exploiting Service Provider Flaw

Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank accounts.

Aug 14·schneier.com

Upcoming Speaking Engagements

Bruce Schneier shares his upcoming speaking engagements, including LAcon V in Anaheim, California, USA, a League of Women Voters event, Elevate Festival in Toronto, Canada, CanSecWest 2026 in Vancouver, Canada, and ATTENTION: Democracy, Rebuilt in Montreal, Canada.

Aug 14·bleepingcomputer.com

Hackers Exploit macOS Screen Sharing Flaw to Deploy Monero Miner

NCSC warns of active macOS vulnerability exploitation for cryptocurrency mining.

Aug 14·bleepingcomputer.com

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

The article discusses the evolving attack chain in Google Workspace security, where OAuth tokens become the entry point for attackers, and AI agents are increasingly used to exploit vulnerabilities. The author argues that security teams need to rethink their defenses to a…