Jamf Threat Labs uncovers X ad campaign delivering macOS malware
Jamf Threat Labs identified a malicious campaign on X (formerly Twitter) that used sponsored advertisements to impersonate the popular macOS utility DynamicLake. The ads redirected users to a counterfeit domain (dynamicmacisland.com) that instructed them to open the Terminal and execute a command, installing a variant of the Atomic Stealer malware, tracked by Jamf as “MacSync.”
The payload collects passwords, browser cookies, crypto‑wallet files and other personal data from infected Macs. Researchers warned that the technique—known as ClickFix—relies on users trusting a verified advertising account and the visual similarity of the fraudulent page to the legitimate DynamicLake site. Users are advised to verify URLs carefully, download software only from official developer sites or the Mac App Store, and keep macOS and security tools up to date.