Researchers reported multiple social-engineering campaigns targeting macOS users with fake CAPTCHA and ClickFix lures that trick victims into copying and pasting malicious commands into Terminal, shifting execution to the user and bypassing traditional app-download protections. One campaign delivered Atomic macOS Stealer (AMOS) through trojanized cracked applications and malicious Terminal instructions, stealing credentials, browser data, cryptocurrency wallets, Telegram data, VPN profiles, keychain contents, Apple Notes, and files from common user folders before compressing and exfiltrating them over HTTP/HTTPS. Trend Micro separately documented multistage fake CAPTCHA attacks that also led to infostealers and remote-access trojans, underscoring the broader use of human-verification themes to launch malware chains.
A separate July 2026 macOS campaign used a fake TrustKey verification page on Cloudflare Pages, a Cloudflare Worker, and an AppleScript-based loader to install a persistent backdoor named bmodule via LaunchAgent persistence. The malware dynamically resolved live command-and-control infrastructure from a Polygon smart contract using an EtherHiding technique, then fingerprinted hosts, phished macOS login passwords, and fetched tasks to deploy AMOS variants, an interactive shell, or an XMRig cryptominer. Apple said macOS Sequoia has updated runtime protections, while incident reporting shows Terminal-based social-engineering chains remain effective because they rely on users to execute the malicious commands directly.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
NetbyteSEC published a technical analysis of a macOS ClickFix crimekit that used a Cloudflare-hosted lure, AppleScript-based persistence, and Polygon smart-contract EtherHiding to resolve live C2 infrastructure. The report identified the bmodule backdoor, associated wallets, and the current decoded C2 hostname.
TrendAI reported an Atomic macOS Stealer campaign that targeted macOS users through trojanized cracked applications and malicious Terminal copy-paste commands. The report described rotating redirector and landing-page domains, data theft, persistence via LaunchDaemon, and exfiltration to attacker-controlled infrastructure.
The macOS ClickFix operators repeatedly updated server URLs stored in a Polygon smart contract, rotating operational command-and-control domains over time after earlier test values such as rutube.ru, facebook.com, vk.com, and example.com. NetbyteSEC reconstructed the historical C2 sequence from Polygonscan transaction history.
A macOS malware campaign used a ClickFix lure in July 2026, serving a fake TrustKey human-verification page from Cloudflare Pages that instructed victims to paste a malicious command into Terminal. The command fetched a bash script from a Cloudflare Worker, beginning the infection chain.
On-chain activity showed the relay wallet receiving 90.52 POL from a high-volume source wallet and then sending 30.00 POL to the operator wallet that controlled the Polygon-based EtherHiding infrastructure. This funding chain was explicitly anchored to 2026-05-01.
Trend Micro published research on fake CAPTCHA attack chains that deploy infostealers and remote access trojans through multistage payload delivery. The reference establishes the broader social-engineering technique later seen in macOS-focused campaigns.
A malware campaign impersonated an OpenAI Codex download for macOS users, using sponsored search results and Google Sites pages to deliver ClickFix-style Terminal commands. Cato Networks documented OS- and path-aware gating, staged shell-script delivery, and a final Mach-O payload, noting strong overlap with previously documented AMOS delivery activity without definitively attributing the payload to AMOS.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 76 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
8 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourceinfosecurity-magazine.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcenotes.netbytesec.com
Open sourcetrendaisecurity.com
Open sourcetrendmicro.com
Open sourcedeveloper.apple.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.