started · updated
Cybercriminals use fake OpenAI Codex ads to target macOS users
Cybercriminals are utilizing fraudulent Google Ads and Google Sites to host fake download pages for OpenAI Codex, specifically targeting macOS users. The campaign uses sponsored search results to direct developers to convincing landing pages that feature OpenAI branding.
Instead of providing a software installer, the sites employ a technique known as ‘ClickFix’. This method instructs victims to open the macOS Terminal and execute a specific command, which the attackers present as a necessary part of the installation process. In reality, the command executes a multi-stage malware infection by fetching a shell script that downloads a Mach-O executable to the system.
Researchers at Cato Networks identified the campaign, noting that the malicious activity shows significant overlap with the Atomic macOS Stealer (AMOS) infostealer. The malware is designed to run on both Intel-powered and Apple Silicon Macs and includes steps to remove security information used by macOS to flag suspicious downloads.