< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 3 sources · 9 days · First seen · Last updated

macOS malware impersonation campaigns

Overview

Cybercriminals are employing various methods to target macOS users through impersonation and fraudulent software downloads.

Initially, attackers utilized GitHub by creating copycat repositories for popular applications such as VLC Media Player, Figma, Malwarebytes, and 1Blocker. These repositories used anonymous accounts and fake support emails to exploit search engine rankings and direct users to malicious JavaScript hosted on fraudulent pages.

More recent activity has shifted toward using fraudulent Google Ads and Google Sites to impersonate OpenAI Codex. This campaign directs developers to landing pages that utilize a ‘ClickFix’ technique, instructing victims to execute commands in the macOS Terminal under the guise of a necessary installation step. This process triggers a multi-stage malware infection, which researchers have linked to the Atomic macOS Stealer (AMOS) infostealer. The malware is capable of running on both Intel and Apple Silicon systems and includes mechanisms to bypass macOS security flags.

Entities

Google · Cato Networks · OpenAI · GitHub · Atomic macOS Stealer

Timeline

  1. 17 days ago

    [TECHNOLOGY] 3 sources
    Cybercriminals use fake OpenAI Codex ads to target macOS users

    Hackers are using fake OpenAI Codex ads and Google Sites to trick macOS users into running malware via a ‘ClickFix’ technique that prompts victims to execute malicious commands in the Terminal.

  2. 26 days ago

    [TECHNOLOGY] 3 sources
    GitHub hosts malware scam using copycat macOS app repositories

    Malware scammers are using fake GitHub repositories to impersonate popular macOS applications like VLC and Figma to distribute malicious software via SEO manipulation.

Sources

cybernoz.com · cybersecuritynews.com · theregister.com