started · updated
ClickFix malware attacks targeting PC and Mac users
The ClickFix cyberattack method is rapidly spreading, targeting both PC and macOS users by tricking individuals into voluntarily executing malicious commands in their own terminals. According to security firm BlueVoyant, this shift eliminates the previous need for resource-intensive infrastructure, such as SEO manipulation or Microsoft-trusted signing certificates, by substituting technical legitimacy with user-driven execution.
Attackers are utilizing various public services to facilitate these campaigns. Cisco Talos reported the use of publicly published Google Sheets documents, while other actors, including the Russian state-sponsored group Sandworm, have been observed hosting control infrastructure within blockchain-based smart contracts. Netskope identified a campaign involving approximately 5,400 sites beaconing to such infrastructure.
On macOS, security firm Jamf and independent researchers have documented variations of ClickFix that are capable of bypassing Gatekeeper protections. As operating system developers implement new defenses, attackers continue to find methods to circumvent them, making ClickFix a highly efficient means of malware distribution.
Entities
BlueVoyant · Cisco Talos · Jamf · Netskope · Sandworm