{"id":30765,"date":"2026-07-27T15:08:58","date_gmt":"2026-07-27T19:08:58","guid":{"rendered":"https:\/\/www.kaspersky.co.uk\/blog\/?p=30765"},"modified":"2026-07-27T20:25:23","modified_gmt":"2026-07-27T19:25:23","slug":"macos-clickfix-attack","status":"publish","type":"post","link":"https:\/\/www.kaspersky.co.uk\/blog\/macos-clickfix-attack\/30765\/","title":{"rendered":"ClickFix on macOS: how Apple users are being scammed"},"content":{"rendered":"<p>AI is getting better and better at <a href=\"https:\/\/www.kaspersky.com\/blog\/why-captcha-is-disappearing\/56089\/\" target=\"_blank\" rel=\"noopener nofollow\">solving CAPTCHAs<\/a>. This makes website creators\u00a0\u2014 who still need to verify that they\u2019re dealing with humans rather than bots\u00a0\u2014 come up with increasingly sophisticated proof-of-humanity checks. It seems an average user would no longer be surprised if asked to recite a poem\u00a0\u2014 or, say, dance Gangnam Style\u00a0\u2014 just to access certain websites. The latter could double as an age check, but I digress.<\/p>\n<p>Attackers have learned to exploit this variety of sometimes bizarre checks to their advantage. In our blog, we\u2019ve talked more than once about the <a href=\"https:\/\/www.kaspersky.com\/blog\/what-is-clickfix\/53348\/\" target=\"_blank\" rel=\"noopener nofollow\">ClickFix attack technique<\/a>, which is all about slipping a malicious instruction to the victim under the guise of yet another CAPTCHA. Historically, this technique has been used to attack users of Windows-powered devices. However, researchers recently discovered a campaign that targets macOS users. In this post, we talk in more detail about the ClickFix attack technique, the new campaign aimed at Mac users, and the criminals\u2019 goals.<\/p>\n<h2>What is the ClickFix attack technique?<\/h2>\n<p>Many common attacks and scams rely on social engineering, or more simply put \u2014 manipulation. Instead of looking for software vulnerabilities, attackers try to trick the user into doing the dirty work themselves: opening a malicious file, clicking a link to a fake website, sharing sensitive data, or running a harmful command.<\/p>\n<p>The simplest example of social engineering is scam calls, where criminals pose as a boss, neighbor, bank security specialist, police officer\u2026 the list goes on almost indefinitely. And if you think that only, let\u2019s say, not-so-smart users fall for these tricks, you\u2019re wrong: social engineering has been used to <a href=\"https:\/\/www.kaspersky.com\/blog\/social-engineering-cases\/48697\/\" target=\"_blank\" rel=\"noopener nofollow\">hack the CIA chief\u2019s email, hijack the X (Twitter) accounts of Elon Musk and Joe Biden, and steal half a billion dollars<\/a>. In our post, <a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-recognize-social-engineering\/56053\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>They\u2019re reading you like a book: scammers\u2019 favorite tricks<\/strong><\/a>, we take a close look at their favorite techniques\u00a0\u2014 give it a read so you don\u2019t end up sharing company with those famous victims.<\/p>\n<p>The ClickFix attack also relies on social engineering, except the scammers aren\u2019t betting on the victim\u2019s fear of an authority figure, but rather on their trust in technology and their habit of following instructions\u00a0\u2014 even when they don\u2019t quite make sense.<\/p>\n<p>In a classic ClickFix scenario, a user visits a compromised or fake website and, instead of the expected page, sees a notification that there\u2019s an issue. The site might claim that to continue, you need to complete an extra verification check, update your browser, or fix an error.<\/p>\n<div id=\"attachment_56191\" style=\"width: 785px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/86\/2026\/07\/27201108\/macos-clickfix-attack-1.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-56191\" class=\"wp-image-56191 size-full\" title=\"A typical ClickFix attack scenario\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/86\/2026\/07\/27201108\/macos-clickfix-attack-1.png\" alt=\"A typical ClickFix attack scenario\" width=\"775\" height=\"652\"><\/a><p id=\"caption-attachment-56191\" class=\"wp-caption-text\">ClickFix: how to infect your own computer with malware in three easy steps. One of the classic variations of the attack targeting Windows users <a href=\"https:\/\/securelist.ru\/fake-captcha-delivers-lumma-amadey\/110867\/\" target=\"_blank\" rel=\"nofollow noopener\"> Source<\/a><\/p><\/div>\n<p>Next, the victim is prompted to follow a few simple steps that look harmless enough at first glance. Usually, this involves copying some text from the attackers\u2019 website, opening the <em>Run<\/em> window, pasting the text there, and hitting Enter.<\/p>\n<p>In reality, the text is a malicious command that downloads and runs malware on the device. Since the user carries out all the steps themselves, the operating system\u2019s security mechanisms and built-in warnings are often dismissed as just another part of the instructions. In our blog, we\u2019ve covered the typical pretexts used to trick victims into taking dangerous actions; you can read more about them <a href=\"https:\/\/www.kaspersky.com\/blog\/clickfix-attack-variations\/55340\/\" target=\"_blank\" rel=\"noopener nofollow\">here<\/a>.<\/p>\n<p>The ClickFix attack scheme quickly began spawning various spin-offs, such as <a href=\"https:\/\/www.kaspersky.com\/blog\/filefix-attack-windows-file-explorer\/54752\/\" target=\"_blank\" rel=\"noopener nofollow\">FileFix<\/a> and <a href=\"https:\/\/www.kaspersky.com\/blog\/consentfix-microsoft-365-account-hijacking\/56155\/\" target=\"_blank\" rel=\"noopener nofollow\">ConsentFix<\/a>. Until recently, the victims of ClickFix and its variants were mostly Windows users, while Mac fans encountered it <a href=\"https:\/\/www.kaspersky.com\/blog\/share-chatgpt-chat-clickfix-macos-amos-infostealer\/54928\/\" target=\"_blank\" rel=\"noopener nofollow\">much more rarely<\/a>. But lately, the number of ClickFix attacks targeting Apple device owners has been on the rise.<\/p>\n<h2>How does the ClickFix attack on macOS work?<\/h2>\n<p>The ClickFix attack on Macs, as documented by cybersecurity researchers, begins with the <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer\/\" target=\"_blank\" rel=\"noopener nofollow\">classic fake CAPTCHA scenario<\/a>. To pass the proof-of-humanity check, attackers prompt the user to copy a command, open Terminal, and paste the text into it.<\/p>\n<div id=\"attachment_56192\" style=\"width: 2048px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/86\/2026\/07\/27201111\/macos-clickfix-attack-2.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-56192\" class=\"wp-image-56192 size-full\" title=\"Malicious ClickFix command for macOS\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/86\/2026\/07\/27201111\/macos-clickfix-attack-2.png\" alt=\"Malicious ClickFix command for macOS\" width=\"2038\" height=\"554\"><\/a><p id=\"caption-attachment-56192\" class=\"wp-caption-text\">The contents of the command that the user is prompted to run via Terminal. <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer\/\" target=\"_blank\" rel=\"nofollow noopener\"> Source<\/a><\/p><\/div>\n<p>The more interesting part is what happens after the malicious command is run. First, it downloads a malicious DMG\u00a0\u2014 the standard format for disk images containing installation files in macOS \u2014 from a remote server, and saves it to the <em>\/tmp<\/em> temporary folder under a random name. Then the script mounts the disk image without showing it in Finder or creating a desktop icon \u2014 keeping it hidden from the user. After that, the script searches the disk image for an app or installation package, and automatically launches it once found.<\/p>\n<p>One case documented in the researchers\u2019 findings involved the widespread <a href=\"https:\/\/www.kaspersky.com\/blog\/share-chatgpt-chat-clickfix-macos-amos-infostealer\/54928\/\" target=\"_blank\" rel=\"noopener nofollow\">AMOS (Atomic macOS Stealer) infostealer<\/a> being distributed this way. To gain extra privileges on the system, the stealer Trojan displays a fake macOS system authentication window tricking the user into willingly typing in their password.<\/p>\n<h2>What are the attackers\u2019 goals?<\/h2>\n<p>After the malware is installed, the attackers steal literally everything they can get their hands on from the victim\u2019s device. Atomic macOS Stealer extracts sensitive information stored in Chromium-based browsers (Google Chrome, Microsoft Edge, Brave, Opera, Arc, Vivaldi, CocCoc, and Yandex), as well as Firefox-based ones (LibreWolf, SeaMonkey, Tor Browser, Waterfox, and Zen Browser), such as the following:<\/p>\n<ul>\n<li>Cookies<\/li>\n<li>Saved logins and passwords<\/li>\n<li>Auto-fill data<\/li>\n<li>Saved credit and debit cards<\/li>\n<li>Browser profile data<\/li>\n<\/ul>\n<p>On top of all that, the attackers also steal PDF, TXT, and RTF files from the victim\u2019s device. The criminals are especially interested in crypto apps; specifically: desktop crypto wallets like Exodus, Electrum, Atomic Wallet, Wasabi Wallet, Bitcoin Core, Litecoin Core, DashCore, Guarda, Binance Wallet, Dogecoin Wallet, and Tonkeeper. The malware also gathers data from more than 200 cryptocurrency-related browser extensions.<\/p>\n<p>But that\u2019s still not everything\u2026<\/p>\n<p>It also targets the Telegram and Discord desktop apps. The malware doesn\u2019t spare Apple\u2019s ecosystem either \u2014 stealing Safari cookies, notes from Apple Notes, and passwords stored in the built-in Apple Keychain.<\/p>\n<div id=\"attachment_56193\" style=\"width: 3178px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/86\/2026\/07\/27201117\/macos-clickfix-attack-3.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-56193\" class=\"wp-image-56193 size-full\" title=\"What Atomic macOS Stealer does after infection\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/86\/2026\/07\/27201117\/macos-clickfix-attack-3.jpg\" alt=\"What Atomic macOS Stealer does after infection\" width=\"3168\" height=\"1344\"><\/a><p id=\"caption-attachment-56193\" class=\"wp-caption-text\">Once a device is infected, Atomic macOS Stealer whisks away everything valuable. <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer\/\" target=\"_blank\" rel=\"nofollow noopener\"> Source<\/a><\/p><\/div>\n<p>All of the collected information is added to a ZIP archive and uploaded to the attackers\u2019 server. In addition, the malware replaces legitimate versions of hardware crypto wallet apps\u00a0\u2014 specifically Ledger Wallet and Trezor Suite\u00a0\u2014 with malicious fakes.<\/p>\n<p>Together, this trove of data gives attackers broad opportunities to further compromise accounts, steal digital assets, and launch new attacks on behalf of the victim.<\/p>\n<h2>How do I avoid becoming a victim of ClickFix?<\/h2>\n<p>As social engineering attacks continue to grow, users need to be more vigilant than ever. That goes for everything from chatting with strangers on the phone or in messaging apps to everyday online activity.<\/p>\n<ul>\n<li>Never paste commands into your Terminal just because a website asks you to \u2014 whether it\u2019s to pass a verification check, confirm your identity, or view hidden content. No legitimate website will ever ask you to enable its features by manually running commands Terminal.<\/li>\n<li>Never enter your macOS administrator password unless you completely understand what app is asking for it.<\/li>\n<li>Regularly install macOS security updates, or better yet, set them to install automatically by going to <em>System Settings<\/em> \u2192 <em>General<\/em> \u2192 <em>Software Update<\/em> and clicking the <em>i<\/em> icon next to <em>Automatic Updates<\/em>. While recent versions of macOS may warn you when you try to paste suspicious or malicious commands into Terminal, this isn\u2019t a reliable feature. For example, the malicious code shown in the screenshot above didn\u2019t trigger any warnings at all on macOS Tahoe\u00a026.5.2.<\/li>\n<li>Trust the warnings from your operating system and security software rather than the instructions\u00a0\u2014 or even the demands\u00a0\u2014 of websites and apps.<\/li>\n<li>Install a <a href=\"https:\/\/www.kaspersky.co.uk\/mac-antivirus?icid=gb_kdailyplacehold_acq_ona_smm__onl_b2c_kdaily_wpplaceholder_sm-team___kism____a6e35228b1416603\" target=\"_blank\" rel=\"noopener\">reliable security suite for macOS<\/a>. It\u2019ll warn you and block malicious activity if you land on a suspicious website.<\/li>\n<li>Use <a href=\"https:\/\/www.kaspersky.co.uk\/password-manager?icid=gb_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\" rel=\"noopener\">secure password manager<\/a> to keep your login credentials and crypto assets safe from cybercriminals.<\/li>\n<\/ul>\n<blockquote><p>Read our posts to learn about other threats facing Apple device owners:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/ios-macos-fake-crypto-apps\/55665\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Crypto thieves ramping up attacks on Apple users<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/ios-exploits-darksword-and-coruna-in-mass-attacks\/55622\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>The iPhone \u2014 invincible no more: a look at DarkSword and Coruna<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/predator-spyware-ios-recording-indicator-bypass\/55463\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Predator vs. iPhone: the art of invisible surveillance<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/airborne-wormable-zero-click-vulnerability-in-apple-airplay\/53443\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>AirBorne: Attacks on Apple devices through vulnerabilities in AirPlay<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/ios-android-ocr-stealer-sparkcat\/52980\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>SparkCat trojan stealer infiltrates App Store and Google Play, steals data from photos<\/strong><\/a><\/li>\n<\/ul>\n<\/blockquote>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"premium-geek\"><input type=\"hidden\" class=\"placeholder_for_banner\" data-cat_id=\"premium-geek\" value=\"28617\">\n","protected":false},"excerpt":{"rendered":"<p>ClickFix attacks, which were once seen mostly on Windows, are now spreading to macOS. We break down the mechanics of the attack, and ways to protect your device.<\/p>\n","protected":false},"author":2726,"featured_media":30770,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2026],"tags":[14,111,2106,3863,1922,3835,527,36,495,529,131],"class_list":{"0":"post-30765","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-apple","9":"tag-attacks","10":"tag-browsers","11":"tag-clickfix","12":"tag-cryptocurrencies","13":"tag-infostealers","14":"tag-macos","15":"tag-malware-2","16":"tag-social-engineering","17":"tag-threats","18":"tag-tips"},"hreflang":[{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/macos-clickfix-attack\/30765\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/macos-clickfix-attack\/30931\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/macos-clickfix-attack\/25963\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/macos-clickfix-attack\/42382\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/macos-clickfix-attack\/56187\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/macos-clickfix-attack\/30898\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/macos-clickfix-attack\/36430\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/macos-clickfix-attack\/36327\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.co.uk\/blog\/tag\/macos\/","name":"MacOS"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/posts\/30765","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/users\/2726"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=30765"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/posts\/30765\/revisions"}],"predecessor-version":[{"id":30772,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/posts\/30765\/revisions\/30772"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/media\/30770"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=30765"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=30765"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=30765"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}