:

MACOS CLICKFIX ATTACK SILENTLY DEPLOYS INFOSTEALER

INDUSTRY DESK2 MIN READ
TUE, JUN 23, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A new macOS ClickFix campaign leverages Terminal commands to covertly download, mount, and execute info-stealing malware from malicious disk image files. The attack bypasses user awareness by automating the infection process.

Security researchers have identified a new variant of the ClickFix malware campaign targeting macOS users. The attack uses Terminal commands to silently orchestrate a multi-stage infection chain that downloads and mounts malicious DMG (disk image) files without user intervention. The campaign automates three critical steps: downloading the infected disk image, mounting it to the system, and launching the info-stealing payload. By operating through command-line interfaces, the attack evades traditional graphical security warnings that users typically rely on to identify threats. ClickFix represents a broader class of attacks that trick users into executing malicious commands, often through fake browser notifications or support scams claiming system vulnerabilities. This macOS variant refines the approach by minimizing visible activity after the initial user interaction, making detection significantly harder. Once executed, the infostealer component can harvest sensitive data including credentials, browsing history, and personal information. The use of DMG files—a standard macOS distribution format—provides additional legitimacy that can fool both users and security systems. The attack demonstrates how macOS threats are evolving beyond traditional malware delivery methods. While macOS has historically suffered fewer infections than Windows, the platform increasingly attracts sophisticated attackers seeking access to high-value targets. Users should exercise caution with unexpected browser notifications claiming system problems or requiring immediate action. Legitimate Apple and system notifications rarely prompt command execution. Keeping macOS updated, using endpoint protection, and reviewing running processes regularly can help identify suspicious activity. Security teams should monitor for unusual Terminal activity and unexpected DMG mount operations as indicators of ClickFix infection attempts.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cloudflare mitigated over 800 distributed denial-of-service attacks exceeding 1 terabit per second in the second quarter, marking a fivefold increase in large-scale attacks.

1H AGOIndustry Desk

Researchers discovered a critical vulnerability in Zoom's screen-sharing feature that allowed any call participant to take control of another user's device. The flaw has been patched.

1H AGOIndustry Desk

The FBI has confirmed that a North Korean national working remotely successfully infiltrated a US government agency. The case highlights a broader pattern of state-sponsored IT workers targeting US infrastructure, private companies, and cryptocurrency exchanges.

1H AGOSecurity Desk

U.S. federal agencies and South Korea's National Policy Agency have issued a joint warning about Gunra ransomware targeting government and critical infrastructure organizations globally.

5H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.