New macOS ClickFix Attack Silently Mounts DMGs to Deploy Infostealer Malware.

Information
What is ClickFix?
ClickFix is a social engineering attack technique in which threat actors trick users into executing malicious commands or installing malware themselves, rather than exploiting software or operating system vulnerabilities. Attackers typically create fake CAPTCHA pages, Cloudflare verification prompts, or system warning messages that appear legitimate in order to persuade victims to follow malicious instructions.
Incident
Cybersecurity researchers from Palo Alto Networks' Unit 42 have discovered a new ClickFix campaign targeting macOS users. Unlike traditional malware attacks that exploit software vulnerabilities, this campaign relies on social engineering, tricking users into manually executing malicious commands in the macOS Terminal application.
The attackers disguise their malicious activities as a legitimate human verification process, convincing victims to copy and execute commands that ultimately install malware on their devices. The campaign delivers Atomic macOS Stealer (AMOS), a well-known information-stealing malware capable of collecting sensitive user data, including browser credentials, cryptocurrency wallets, and authentication tokens.
This attack demonstrates the continued evolution of ClickFix techniques beyond Windows environments and highlights the growing focus of cybercriminals on macOS users.

Picture 1 Malicious Terminal command used as fake Captcha verification
Attack Flow
The attack begins when victims visit a compromised or malicious website that displays a fake CAPTCHA or "Verify You Are Human" page. The page mimics trusted services such as Cloudflare or other website verification systems to appear legitimate.
Instead of asking users to solve a normal CAPTCHA challenge, the website instructs them to open the Terminal application and paste a command into it. The attackers claim that this action is required to complete the verification process or resolve browser issues.
Once executed, the command silently downloads a malicious Disk Image (DMG) file from a remote server controlled by the attackers. The script then automatically mounts the DMG and launches its contents, allowing the malware installation process to proceed with minimal user interaction.
Unlike traditional malware delivery methods that require users to manually open downloaded files, this technique automates much of the process, making the attack more convincing and reducing the likelihood that victims will recognize malicious behavior.

Picture 2 Infostealer attack flow.
Impact
Once installed, AMOS attempts to collect various types of sensitive information from the infected device, including:
The collected information is then transmitted to the attackers' command-and-control (C2) infrastructure, where it can be used for credential theft, account takeover, financial fraud, identity theft, or sold on underground marketplaces.
Although this campaign does not exploit a software vulnerability in macOS, it represents a significant security threat because it relies on human interaction rather than technical exploitation.
Many users assume that commands provided by websites are safe, particularly when presented during what appears to be a legitimate verification process. This trust allows attackers to bypass many traditional security protections.
Furthermore, the use of DMG files—commonly used for legitimate macOS software distribution—helps the malware blend in with normal user activity, making detection more difficult.
The campaign also illustrates that macOS users are increasingly becoming attractive targets for cybercriminals, challenging the common misconception that Apple's operating system is immune to malware attacks.
Recommendation
1.Never copy and execute Terminal commands from untrusted websites or unknown sources.
2.Be cautious of CAPTCHA or verification pages requesting unusual actions, particularly those involving Terminal or command-line utilities.
3.Deploy Endpoint Detection and Response (EDR) solutions capable of monitoring suspicious Terminal activity and unauthorized DMG execution.
4.Keep macOS and all security software updated with the latest patches.
5.Conduct cybersecurity awareness training to educate users about ClickFix techniques and other forms of social engineering attacks.
The important things is Security systems. We must concern and monitor as usual.
For more information please contact
Email :sales@inetms.co.th
065 149 2822 (Ms.Suphatson )
063 204 4534 (Ms.Atsamaphorn)
065 929 6330 (Ms.Kansinee)
092 257 6902 (Ms.Narusorn)
063 197 7510 (Mr.Yanotai)
065 725 7405 (Ms.Nattharini)
065 725 7405 (Ms.Donraya)
References
Weekly Interesting CVE
| NO. |
CVE Name |
Published Date |
Last Update |
Device/Appplication/OS Target |
Attack Type |
CVSS |
Detail |
Solution |
Reference |
|---|---|---|---|---|---|---|---|---|---|
| 1 |
CVE-2026-20262 |
15/6/2026 |
15/6/2026 |
Cisco Catalyst SD-WAN Manager versions 20.9.9.1, 20.12.7.1, 20.15.4.4, 20.15.5.2, 20.18.3, 26.1.1.1, and earlier versions. |
Arbitrary File Write |
6.8 |
This vulnerability is a file upload flaw caused by insufficient input validation. It allows an authenticated user, even with low privileges, to create or overwrite files on the system. This could potentially lead to privilege escalation to root and full system compromise. |
Update to versions 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, and 26.1.1.2. |
|
| 2 |
CVE-2026-46769 |
06/17/2026 |
06/19/2026 |
Oracle Application Development Framework versions 12.2.1.4.0 and 14.1.2.0.0 |
Application Exploitation |
8.7 |
This vulnerability is easily exploitable by an attacker with high-level privileges who can access the system over the network via HTTP. If the attack is successful, it can allow the attacker to gain control over the Oracle Application Development Framework (ADF) system. |
There has been no update from Oracle yet |
|
| 3 |
CVE-2026-46461 |
17/6/2026 |
17/6/2026 |
Dell Server Hardware Manager versions prior to 3.2.2. |
Local Privilege Escalation (LPE) |
7.8 |
This is a vulnerability in Dell Server Hardware Manager caused by improper access control. It allows a low-privileged user to escalate privileges on the system, provided they already have local access to the target machine. |
Update Dell Server Hardware Manager to version 3.2.2. |
|
| 4 |
CVE-2026-20253 |
10/6/2026 |
19/6/2026 |
Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7 |
Missing Authentication |
9.8 |
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. |
Upgrade Splunk Enterprise to version 10.2.4 and 10.0.7 |
|
| 5 |
CVE-2026-12450 |
17/6/2026 |
17/6/2026 |
Google Chrome prior to 149.0.7827.155 |
Improper Privilege Management |
6.5 |
Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. |
Upgrade Google Chrome to version 149.0.7827.155 |
Malware News or Campaign IOC/IOA | EN
|
No |
Campaign Name |
Detection Date |
Attack Type |
Description |
Mitigation/Remediation |
|---|---|---|---|---|---|
| 1 |
Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline |
17/06/2026 |
Remote Access Trojan, Privilege Escalation, |
Security researchers reported that a junior hacker named “Poisson” leveraged tools like Tailscale and OpenSSH to establish persistent backdoor access on victim machines. Even after the command‑and‑control (C2) server used to manage the malware was taken down, he was able to reconnect immediately once the infrastructure came back online. The incident targeted a small automotive business in France, where Poisson deployed the Havoc Demon agent running in memory, along with VBScript and PowerShell loaders to execute code without leaving disk artifacts. He attempted privilege escalation using a command that required the victim to click “Yes” in a UAC prompt, highlighting his lack of sophistication.What raised concern was his installation of OpenSSH Server and linking of compromised machines to his own Tailscale network, enabling direct access without opening public ports or relying on the C2. Despite the amateur nature of the attack—using free services and low‑cost VPS hosting—Poisson successfully compromised four machines and achieved effective persistence. This demonstrates that simply shutting down a C2 server is insufficient if attackers have already created alternative access channels. Organizations should therefore monitor for unauthorized network services like Tailscale or OpenSSH, and watch for suspicious in‑memory activity or scheduled tasks to prevent stealthy and resilient intrusions. |
|
Ref: https://thehackernews.com/2026/06/junior-hacker-used-tailscale-and.html
30 June 2026
Viewed 80 time