Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators ClickFix campaign uses fake macOS utilities lures to deliver infostealers

quantumdataserver5.homes

TLP:CLEAR
Active

Domain

Description

Threat actors are leveraging ClickFix-style social engineering tactics to distribute infostealers targeting macOS users through fake system utility lures. Attackers host malicious Terminal commands on blog sites and content platforms, disguised as troubleshooting advice for macOS issues. When executed, these commands download infostealers including Macsync, Shub Stealer, and AMOS, which exfiltrate browser credentials, cryptocurrency wallets, iCloud data, Keychain entries, and media files. The campaign has evolved to use Terminal-based script execution that bypasses Gatekeeper verification. Three distinct campaigns employ different tradecraft, with some replacing legitimate cryptocurrency wallet applications with trojanized versions and establishing persistence through LaunchAgents and LaunchDaemons that masquerade as legitimate services.

Sightings (0)

No sightings recorded yet

Details

Name / Label
ClickFix campaign uses fake macOS utilities lures to deliver infostealers
Pattern Type
STIX
Confidence
75%
Valid From
May 10, 2026 05:43
Total Sightings
0
Added
May 10, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of quantumdataserver5.homes

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.