ClickFix campaigns use fake AI installers to push MacSync infostealer on macOS

March 22, 20262 min read2 sources
Share:
ClickFix campaigns use fake AI installers to push MacSync infostealer on macOS

Researchers have identified three separate ClickFix campaigns delivering a macOS information stealer called MacSync through fake AI tool installers, according to The Hacker News. The attacks do not rely on a software flaw. Instead, they trick users into copying and executing terminal commands, which then fetch and run the malware.

In these campaigns, victims are lured by bogus AI tool installer pages and told to complete installation steps manually. Once executed, the command chain can download MacSync, a macOS information stealer.

The main risk is that the attack bypasses the assumptions many users make about malware infections. There is no exploit, no drive-by download, and often no obvious warning beyond the request to paste a command into Terminal.

The MacSync activity shows a playbook adapted to the strong demand for AI tools, where users may be more willing to install apps from unfamiliar sites and follow unusual setup instructions.

Share:

// SOURCES

// RELATED

NIST scales back vulnerability data enrichment after 263% surge in submissions

NIST is limiting detailed analysis in its National Vulnerability Database (NVD) due to a massive increase in submissions, impacting security teams.

2 min readApr 18

Three Microsoft Defender zero-days actively exploited; two still unpatched

Security firm Huntress warns of active exploitation of three Microsoft Defender zero-days, codenamed BlueHammer, RedSun, and UnDefend. Two remain unpa

6 min readApr 18

London healthcare faces months of disruption after ransomware attack on key supplier

A major ransomware attack on pathology provider Synnovis has caused severe, ongoing disruption to London hospitals, highlighting critical supply chain

6 min readApr 18

Most 'AI SOCs' are just faster triage, and that's not enough

Many AI security tools only speed up alert analysis, failing to reduce analyst workload. Experts argue real gains require AI that automates response a

2 min readApr 17