macOS ClickFix Campaign Tricks Users Into Running Malicious Terminal Commands
This attack exploits human trust by presenting fake CAPTCHA pages that instruct users to paste and execute malicious Terminal commands, bypassing traditional malware delivery defenses entirely. The social engineering technique known as ClickFix is particularly dangerous because it weaponizes the user themselves, making security tools that scan for malicious downloads less effective. Once executed, the command silently mounts a DMG file and deploys the Atomic macOS Stealer, exfiltrating credentials, Keychain data, and cryptocurrency wallet information. This matters because macOS users often operate under a false sense of security, and attacks that leverage native OS tools like Terminal are harder to detect with conventional antivirus solutions.
Tactical Insight
Immediate actions
- Educate users to never copy-paste Terminal commands from websites, browser pop-ups, or CAPTCHA-style prompts regardless of how legitimate they appear.
- Deploy endpoint detection and response (EDR) tools capable of monitoring and alerting on suspicious Terminal/shell command executions on macOS devices.
- Review and restrict which users have the ability to install or mount DMG files on managed macOS endpoints.
Long-term improvements
- Enforce macOS Application Control policies via MDM (e.g., Jamf or Intune) to block execution of unsigned or untrusted binaries and mounted disk images.
- Implement DNS filtering and web proxies to block access to known malicious or newly registered domains used in phishing and ClickFix campaigns.
- Establish a formal security awareness training program that includes simulated social engineering scenarios targeting macOS users specifically.
Detection measures
- Configure centralized logging to capture Terminal command history and shell process spawning events across all macOS endpoints.
- Set up alerts for anomalous DMG mount events or processes spawned from user-interactive shell sessions outside of normal business activity.
- Monitor for known AMOS indicators of compromise (IOCs) such as suspicious outbound connections to C2 infrastructure or access patterns targeting Keychain and browser credential stores.