ClickFix malware campaign targets Mac users searching for help
A widespread macOS malware campaign dubbed ClickFix is actively harvesting cryptocurrency wallet keys, iCloud credentials, and saved passwords from victims by tricking them into running terminal commands hidden in fake troubleshooting guides posted on legitimate platforms. The technique bypasses Apple’s standard security inspections and has already spawned at least three distinct malware families targeting crypto users since late 2025.
- Microsoft identified three malware installer variants (loader, script, helper) all harvesting iCloud data, passwords, and crypto keys from Exodus, Ledger, and Trezor wallets.
- Fake macOS guides posted on Medium, Craft, and Squarespace direct users to copy terminal commands that download and execute malware without triggering Gatekeeper inspection.
- Attackers have also replaced legitimate crypto wallet apps with trojanized versions designed to monitor transactions and steal funds in real time.
- Late 2025 Campaign launch date when ClickFix attacks on Mac users began escalating.
- 3 Distinct malware families identified (AMOS, Macsync, SHub Stealer) deployed across multiple installer campaigns.
- 3 Major crypto wallet apps targeted for replacement with trojans (Trezor, Ledger, Exodus).
A coordinated malware operation is actively targeting macOS users by posting fabricated system troubleshooting guides on high-authority publishing platforms, then harvesting cryptocurrency assets, financial credentials, and personal data once victims execute hidden commands in Terminal.
Microsoft’s Defender Security Research Team disclosed the campaign in a detailed analysis, identifying three separate malware families deployed under the unified “ClickFix” social engineering framework.
The attack chain exploits a critical gap in macOS security: when users manually run commands in Terminal, Apple’s Gatekeeper code-signing and notarization system is bypassed entirely, allowing unsigned payloads to execute with user privileges.
The campaign has been operational since late 2025 and deliberately targets Mac owners searching for solutions to common problems like freeing disk space or resolving system errors, making the fake guides appear as organic search results to users in genuine distress.
Microsoft identifies three malware families exploiting macOS Gatekeeper bypass via terminal commands
Each of the three installer variants, classified as a loader, a script-based payload, and a helper tool, performs the same core function: extracting sensitive data, establishing persistence mechanisms, and exfiltrating stolen information back to attacker-controlled servers.
Once deployed, the malware families AMOS, Macsync, and SHub Stealer immediately begin harvesting iCloud account credentials and Telegram session data, then scour the victim’s file system for private documents and photos under 2 megabytes in size.
The most damaging capability targets cryptocurrency custody: the malware extracts private keys stored by Exodus, Ledger, and Trezor wallet applications, then harvests saved usernames and passwords from Chrome and Firefox browsers.
The social engineering sophistication escalates after the initial infection takes hold. The malware displays a fake system dialog requesting the user’s macOS administrator password, claiming it must install a “helper tool” for functionality.
If the victim enters their credentials, a request that appears legitimate given the malware’s already-successful execution, the attacker gains full read-write access to all files and system settings, enabling complete account takeover and persistent backdoor access.
In a particularly aggressive variant, researchers documented cases where attackers deleted legitimate wallet applications and replaced them with trojaned versions that monitor outgoing transactions in real time.
ClickFix guides on Medium and Squarespace sidestep Apple security by using native terminal utilities
The attack vector relies on a fundamental asymmetry in how macOS enforces code signing: Gatekeeper inspects applications launched through the Finder GUI or from standard app bundles, but code executed directly by the user in Terminal bypasses this check entirely.
Attackers post fake macOS troubleshooting articles on Medium, Craft, and Squarespace, platforms with high search engine authority and user trust, then instruct readers to copy a single terminal command and paste it into their Terminal application.
That command, disguised as a legitimate system utility, downloads and executes the malware payload directly in memory without ever writing an executable file to disk.
Security researchers observed that attackers use native macOS utilities including curl for downloading payloads and osascript for executing them, a fileless technique that circumvents standard antivirus detection mechanisms designed to scan disk-based binaries.
This approach leaves minimal forensic artifacts, allowing the malware to establish persistence and exfiltrate data before security tools can identify the compromise.
One variant of the loader campaign includes a kill switch: the malware ceases all execution if it detects a Russian keyboard layout, suggesting the attackers are either based in Russia or deliberately avoiding infecting users in that country.
North Korean threat groups deploy ClickFix against crypto developers and fintech infrastructure
The ClickFix technique has attracted adoption from state-sponsored threat actors, significantly raising the stakes for institutional crypto investors and infrastructure operators.
Security researchers from ANY.RUN identified a Lazarus Group campaign called “Mach-O Man” that uses the same terminal command injection method, but targets fintech and cryptocurrency development environments where macOS is heavily deployed.
Rather than mass-targeting individual wallet users through search engine poisoning, the Lazarus operation sends carefully crafted fake meeting invitations to software engineers and developers at crypto trading firms, attempting to compromise build systems and development credentials at scale.
The North Korean group Famous Chollima has similarly weaponized the broader attack surface by introducing malicious npm packages into cryptocurrency trading projects through AI-generated code contributions, allowing attackers to compromise open-source dependency chains used by trading infrastructure.
These advances indicate that ClickFix and related terminal-injection techniques are transitioning from consumer-targeted campaigns into tools for sophisticated supply chain attacks against institutional market participants.
For crypto exchanges, trading platforms, and custody operators, the implication is stark: developers and operations staff using macOS systems are now targets for both commodity malware campaigns and nation-state actors seeking to compromise critical infrastructure.
An attacker who successfully compromises a developer’s macOS system through ClickFix gains access to private keys, API credentials, deployment scripts, and source code repositories used to manage customer funds.
Wallet applications become trojanized on compromised systems, enabling real-time transaction monitoring
The replacement of legitimate Trezor Suite, Ledger Wallet, and Exodus applications with trojaned versions represents an escalation in attack sophistication.
Rather than simply stealing wallet keys once at compromise time, the trojanized apps allow attackers to monitor every transaction initiated by the victim, giving them visibility into fund flows and allowing them to identify high-value targets for follow-up attacks.
An institutional investor or trading desk operator whose macOS system is compromised through ClickFix may unknowingly continue using a fake wallet app that reports all outgoing transactions and private key operations back to the attacker’s infrastructure.
This attack pattern also extends to exchange connectivity: if a developer or trader’s macOS system is compromised, an attacker can modify API client libraries, authentication modules, or deployment configurations to siphon API keys and session tokens used to access exchange accounts.
The trojaned wallet replacement serves as both an intelligence-gathering tool and a final stage payload, allowing attackers to study victim behavior before executing large-scale theft or transaction manipulation.
Institutional crypto firms should immediately audit macOS deployments for evidence of ClickFix compromise, including the presence of unexpected helper tools, modified wallet applications, or anomalous outbound connections from development systems. The open question remains whether adoption of ClickFix by state-sponsored groups like Lazarus and Famous Chollima will trigger a coordinated takedown of the Medium, Craft, and Squarespace pages hosting the fake guides, or whether platform enforcement will continue to lag detection by security researchers.