Threat actors are increasingly using ClickFix social-engineering pages that masquerade as CAPTCHA checks, browser errors, or verification prompts. The pages instruct victims to copy and execute commands—often through the Windows Run dialog or terminal—turning the victim into the execution mechanism for malware, credential theft, and follow-on compromise. Recent reporting shows the technique has matured into more convincing, dynamically delivered lures and is being tracked as a significant web-based malware-delivery vector.
One campaign attributed to Russian-speaking operators used Spectrum-themed pages and dynamic content delivery to distribute a variant of Atomic macOS Stealer (AMOS). The activity demonstrates that ClickFix is not limited to Windows or generic fake verification pages: attackers are tailoring branded lures and payload delivery to target macOS users and steal browser data, credentials, cryptocurrency-wallet information, and other sensitive files. Organizations should train users never to run commands supplied by websites and monitor for suspicious shell, PowerShell, terminal, or Run-dialog activity initiated after browser sessions.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
A Spectrum-themed dynamic-delivery campaign used ClickFix to distribute a variant of Atomic macOS Stealer (AMOS), attributed in the reference title to Russian-speaking hackers.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
netlas.io
Open sourcecloudsek.com
Open sourcepushsecurity.com
Open sourceweb-assets.esetstatic.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.