A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)

Malware Alert: Macfinger ClickFix Campaign Spreads Information Stealer Malware on Macs

A sophisticated malware campaign targeting macOS users has been detected, and its tactics are unlike any other previously seen in the wild. The Macfinger ClickFix campaign has been active for days, infecting multiple systems with a custom-built information stealer that collects sensitive data from compromised machines.

The malware is delivered via a fake CAPTCHA/verification page, which injects malicious text into the system’s clipboard. When executed, this text retrieves a loader from a remote server, saving it to the user’s Library/Caches directory as com.apple.periodic. The script then checks the system’s architecture and downloads the corresponding payload – either an arm64 or x86_64 Mach-O binary.

Upon successful execution, the malware reports back to its command-and-control (C2) server using a unique URL pattern. Post-infection C2 traffic reveals that the infected host sends various types of data to the server, including exfiltrated credentials and sensitive information. What’s striking about this campaign is the use of websocket traffic for C2 communication – a departure from the typical HTTP-based communication used by other malware families.

Experts have compared this malware to Atomic macOS (AMOS) Stealer, but it appears to be a distinct entity with its own set of features and behaviors. The persistence mechanism and data collection methods differ significantly from those seen in AMOS Stealer, making it a unique threat actor in the wild.

The Macfinger ClickFix campaign’s use of sophisticated techniques and custom-built malware makes it a formidable adversary for macOS users. As this campaign continues to evolve, researchers and cybersecurity experts are working tirelessly to understand its full scope and impact.

So, what can you do to protect yourself? For now, remain vigilant and avoid clicking on suspicious links or engaging with unfamiliar CAPTCHA/verification pages. Regularly back up your data and keep your operating system and software up-to-date. Monitor your account activity closely, and be cautious of any unusual login attempts or password resets.

While the Macfinger ClickFix campaign may seem like a high-level threat, its impact is very real – affecting users worldwide who have fallen victim to this sophisticated information stealer malware. Stay informed, stay vigilant, and take proactive steps to secure your online presence.


Source: SANS ISC — 2026-09-25