Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 3 sources · 9 days · First seen · Last updated
macOS malware impersonation campaigns
Overview
Cybercriminals are employing various methods to target macOS users through impersonation and fraudulent software downloads.
Initially, attackers utilized GitHub by creating copycat repositories for popular applications such as VLC Media Player, Figma, Malwarebytes, and 1Blocker. These repositories used anonymous accounts and fake support emails to exploit search engine rankings and direct users to malicious JavaScript hosted on fraudulent pages.
More recent activity has shifted toward using fraudulent Google Ads and Google Sites to impersonate OpenAI Codex. This campaign directs developers to landing pages that utilize a ‘ClickFix’ technique, instructing victims to execute commands in the macOS Terminal under the guise of a necessary installation step. This process triggers a multi-stage malware infection, which researchers have linked to the Atomic macOS Stealer (AMOS) infostealer. The malware is capable of running on both Intel and Apple Silicon systems and includes mechanisms to bypass macOS security flags.
Entities
Google · Cato Networks · OpenAI · GitHub · Atomic macOS Stealer
Timeline
-
17 days ago
[TECHNOLOGY] 3 sourcesCybercriminals use fake OpenAI Codex ads to target macOS usersHackers are using fake OpenAI Codex ads and Google Sites to trick macOS users into running malware via a ‘ClickFix’ technique that prompts victims to execute malicious commands in the Terminal.
-
26 days ago
[TECHNOLOGY] 3 sourcesGitHub hosts malware scam using copycat macOS app repositoriesMalware scammers are using fake GitHub repositories to impersonate popular macOS applications like VLC and Figma to distribute malicious software via SEO manipulation.
Sources
cybernoz.com · cybersecuritynews.com · theregister.com