New macOS ClickFix attack silently mounts DMGs to push infostealer
A new macOS ClickFix campaign uses Terminal commands to download and launch info-stealing malware from malicious DMG files. The campaign infects Mac devices with the Atomic macOS Stealer, which steals browser credentials and cryptocurrency wallet data.
Intelligence analysis by Llama 3.3 70B

The ClickFix attack begins with a fake CAPTCHA page that tricks users into executing a malicious Terminal command, which downloads and mounts a DMG file containing the malware.
Imagine you're on a website and it asks you to do something to prove you're human. But instead of just checking a box, it asks you to type a special command into your computer. That's what's happening in this attack. The bad guys are tricking people into typing a command that lets them steal sensitive information, like passwords and cryptocurrency.
Analysis
The Evolution of ClickFix Attacks
The ClickFix technique has been used by threat actors to distribute malware, and its popularity has grown in the past year. This campaign combines social engineering with the use of Terminal commands to silently download and launch malware, making it a more sophisticated and stealthy attack.
The use of fake CAPTCHA pages to trick users into executing malicious commands is a common tactic used by attackers. This campaign takes it a step further by using the Terminal command to download and mount a DMG file, which contains the malware. This approach allows the attackers to bypass traditional security measures and infect the device without the user's knowledge.
The Atomic macOS Stealer
The malware used in this campaign is the Atomic macOS Stealer, which is a highly sophisticated infostealer that can steal a wide range of sensitive data, including browser credentials, cryptocurrency wallet data, and user documents. The stealer is designed to target multiple browsers, including Chromium-based and Firefox-derived browsers, and can steal various types of data, including cookies, login databases, and autofill information.
The stealer also targets cryptocurrency wallet data, including Exodus, Electrum, and Atomic Wallet, and can replace legitimate installations of Ledger Live and Trezor Suite with malicious versions. This suggests that the attackers are highly motivated to steal cryptocurrency and other sensitive data, and are willing to use sophisticated tactics to achieve their goals.
Mitigation and Prevention
To mitigate the risk of ClickFix attacks, users should be cautious when websites instruct them to open Terminal and execute commands. It is especially important to be wary of commands that claim to be part of CAPTCHA verifications, browser fixes, or other troubleshooting steps. Users should never execute a command that they do not fully understand, and should always verify the authenticity of the command before running it.
Security teams should also be aware of the growing threat of ClickFix attacks and take steps to educate users about the risks. This can include providing training on how to identify and avoid social engineering attacks, as well as implementing security measures to detect and prevent malware infections.
Key points
- ClickFix attack uses Terminal commands to download and launch malware
- Malware steals browser credentials and cryptocurrency wallet data
- Attack begins with fake CAPTCHA page that tricks users into executing malicious command
As security teams become more aware of the ClickFix threat, they can take steps to educate users and implement measures to prevent these types of attacks. By being cautious and vigilant, users can reduce the risk of falling victim to these attacks and protect their sensitive data.
The growing sophistication of ClickFix attacks and the use of highly effective malware like the Atomic macOS Stealer suggest that these types of attacks will continue to be a significant threat to macOS users. If left unchecked, these attacks could lead to significant data breaches and financial losses, highlighting the need for increased awareness and vigilance among users and security teams.


