ClickFix campaigns use fake AI installers to push MacSync infostealer on macOS

March 22, 20262 min read2 sources
Share:
ClickFix campaigns use fake AI installers to push MacSync infostealer on macOS

Researchers have identified three separate ClickFix campaigns delivering a macOS information stealer called MacSync through fake AI tool installers, according to The Hacker News. The attacks do not rely on a software flaw. Instead, they trick users into copying and executing terminal commands, which then fetch and run the malware.

In these campaigns, victims are lured by bogus AI tool installer pages and told to complete installation steps manually. Once executed, the command chain can download MacSync, a macOS information stealer.

The main risk is that the attack bypasses the assumptions many users make about malware infections. There is no exploit, no drive-by download, and often no obvious warning beyond the request to paste a command into Terminal.

The MacSync activity shows a playbook adapted to the strong demand for AI tools, where users may be more willing to install apps from unfamiliar sites and follow unusual setup instructions.

Share:

// SOURCES

// RELATED

Meta settles bellwether lawsuit alleging addictive design harmed student mental health

Meta's confidential settlement with a Washington school district marks a pivotal moment in the massive litigation against social media's psychological

6 min readMay 24

Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network

A sophisticated zero-day attack on Huawei routers allegedly caused Luxembourg's 2023 national telecom outage, raising severe global security concerns.

6 min readMay 23

MiniPlasma Windows 0-day enables SYSTEM privilege escalation on fully patched systems

A newly disclosed 0-day flaw, MiniPlasma, allows attackers to gain full SYSTEM control on patched Windows systems, with a public PoC accelerating risk

6 min readMay 18

The ransomware dilemma: why more than half of security chiefs would pay the price

A new survey reveals 56% of CISOs would consider paying a ransom, highlighting the intense pressure to restore operations despite official guidance.

6 min readMay 16