Attackers are increasingly compromising macOS systems through ClickFix and related social-engineering lures that trick users into pasting malicious commands into Terminal, often behind fake Cloudflare checks, bogus troubleshooting steps, fraudulent support messages, or compromised websites. A large campaign tied to hundreds of hacked WordPress sites served platform-specific payloads and used the Polygon blockchain to hide command-and-control locations, while the macOS payload ran largely in memory, harvested Keychain data, browser information, SSH keys, screenshots, and other files, then staged stolen data in /tmp/osalogging.zip before exfiltrating it. Researchers said the technique does not rely on a macOS software flaw, but on convincing victims to execute attacker-supplied commands themselves.
Threat reporting indicates the tactic has become a dominant initial-access method against Mac users, especially cryptocurrency holders and developers, and that recent Apple paste warnings in Terminal have already been bypassed through Script Editor abuse. Separate intrusion research linked cryptocurrency-focused activity to malware families including DEEPBREATH, SUGARLOADER, and CHROMEPUSH, showing how post-compromise tooling on macOS can escalate from social engineering to broad credential and data theft by targeting TCC.db, Keychain contents, Chromium-based browsers, Telegram data, and Apple Notes. Security teams are being urged to prioritize behavioral detection, cross-platform response, and user controls that prevent unverified command execution on Macs.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Moonlock reported that by mid-2026, ClickFix had become the dominant initial access technique targeting macOS users, especially cryptocurrency holders and software developers, with attackers reusing tradecraft associated with DPRK-linked operations.
LevelBlue described a broad ClickFix campaign on hundreds of compromised WordPress sites that used fake Cloudflare verification pages to trick macOS users into pasting malicious Terminal commands. The malware ran in memory and used the Polygon blockchain to retrieve command-and-control infrastructure.
A growing social-engineering scam targeting Apple users was reported in which victims are persuaded through phishing, fake support, and fraudulent sites to paste malicious commands into Terminal, enabling malware installation, remote access, data theft, and persistence.
Recent macOS versions introduced safeguards that warn users when pasting commands into Terminal from external sources and block known malicious scripts. These protections were later noted as being bypassed through Script Editor abuse in macOS Tahoe 26.4.
Mandiant described a macOS intrusion attributed to UNC1069 in which DEEPBREATH manipulated the TCC database to gain broad access to sensitive data, while SUGARLOADER was used to deploy the CHROMEPUSH malicious Chromium extension stealer.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
moonlock.com
Open sourcelevelblue.com
Open sourcecysecurity.news
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.