Multiple reports highlighted ClickFix-style social engineering that convinces users to paste attacker-supplied commands into a terminal, leading to infostealer installation. Malwarebytes documented a macOS lure impersonating CleanMyMac via cleanmymacos[.]org, where victims are instructed to run a Terminal command that prints a reassuring message, decodes a hidden (base64) destination, and then downloads and executes a remote shell script via zsh. The resulting payload installs SHub Stealer, which targets saved passwords, browser data, Apple Keychain contents, Telegram sessions, and cryptocurrency wallets; it can also tamper with wallet applications (e.g., Exodus, Atomic Wallet, Ledger Live) to enable later theft of recovery phrases.
Microsoft threat intelligence (as reported by The Hacker News) described a parallel Windows ClickFix campaign that shifts from the traditional Run-dialog paste to Windows Terminal (wt.exe) using the Win + X → I shortcut, exploiting the tool’s administrative legitimacy to reduce suspicion and evade detections tuned to Run-dialog abuse. In that chain, users paste a hex-encoded/XOR-compressed command that spawns additional Terminal/PowerShell stages to decode scripts, download a ZIP payload plus a legitimate-but-renamed 7-Zip binary, extract additional components, establish persistence via scheduled tasks, configure Microsoft Defender exclusions, and ultimately deploy Lumma Stealer (including use of QueueUserAPC() for injection).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
By March 31, 2026, Moonlock Lab documented a ClickFix campaign targeting crypto, Web3, blockchain, VC, and fintech professionals through fake LinkedIn recruiter personas, Calendly links, and spoofed Zoom or Google Meet pages. The campaign used fake verification prompts to copy OS-specific Terminal commands that launched multi-stage payloads stealing credentials and crypto wallet data, with tradecraft overlaps noted with DPRK-linked UNC1069 and Contagious Interview activity.
Analysis of the macOS campaign showed SHub stealing Keychain, browser, iCloud, Notes, Telegram, and wallet data, backdooring Electron-based cryptocurrency wallet apps to capture seed phrases and passwords, and persisting via a LaunchAgent masquerading as Google Keystone.
By March 6, 2026, researchers reported that the fake site cleanmymacos[.]org was impersonating CleanMyMac and using a ClickFix-style Terminal command to install SHub Stealer on macOS systems.
On March 6, 2026, Microsoft publicly revealed the Windows Terminal-focused ClickFix campaign, including a second infection path involving batch/VBS/MSBuild execution and possible EtherHiding through blockchain RPC endpoints, along with defensive guidance.
In the observed February campaign, pasted Terminal commands decoded and launched multi-stage payloads that downloaded archives and tools, established persistence with scheduled tasks, altered Microsoft Defender exclusions, and ultimately deployed Lumma Stealer to steal browser credentials from Chrome and Edge.
Microsoft Threat Intelligence observed a widespread ClickFix social-engineering campaign in February 2026 that shifted from the Windows Run dialog to Windows Terminal, using fake CAPTCHA, verification, and troubleshooting lures to trick users into pasting malicious commands.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
hackernoon.com
Open sourcescworld.com
Open sourcehackread.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcemalwarebytes.com
Open sourcethehackernews.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.