🟠 High | Source: The Hacker News
A large-scale macOS social engineering campaign is using over 250 fake websites to trick users into running malicious commands, a technique known as ClickFix. The infrastructure now fingerprints visitors’ browsers server-side to determine whether to display the malware lure, effectively hiding the attack from automated security scanners and researchers. This evasion capability makes the campaign harder to detect and takedown, increasing the risk to targeted Mac users.
Security Architect’s Take: Review endpoint detection coverage for macOS devices across your estate and ensure policies block users from executing commands pasted from browser prompts. Consider pushing DNS-layer blocking for newly registered or low-reputation domains, and validate that your security tooling can detect ClickFix-style lures rather than relying solely on crawler-based detection which this campaign is explicitly designed to evade.
Original advisory: Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures