newstrooper newstrooper
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Reading: The new Atomic Macos Stealer campaign targets Apple users by exploiting Clickfix
Share

News Trooper

Your Global Insight, Delivered Daily.

Search
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Follow US
© 2025 All Rights Reserved | Powered by News Trooper News
News Trooper > Technology > The new Atomic Macos Stealer campaign targets Apple users by exploiting Clickfix
Technology

The new Atomic Macos Stealer campaign targets Apple users by exploiting Clickfix

June 6, 2025 5 Min Read
Share
The new Atomic Macos Stealer campaign targets Apple users by exploiting Clickfix
SHARE

Cybersecurity researchers are warning against a new malware campaign that employs ClickFix social engineering tactics to download information steeler malware called Atomic Macos Stealer (AMOS) on Apple Macos Systems.

According to CloudSek, the campaign is known to harness the Typosquat domain by mimicking the US telecom provider spectrum.

“MACOS users will be provided with malicious shell scripts designed to steal system passwords and download AMOS variants for further exploitation,” security researcher Koushik Pal said in a report published this week. “This script uses native MacOS commands to harvest credentials, bypass security mechanisms, and execute malicious binaries.”

This activity is considered to be a work of Russian-speaking cybercriminals, as there are Russian comments in the source code of the malware.

The attack starts at a web page that is impersonating the spectrum (“PanelSpectrum(.)net” or “spectrum-ticket(.)net”). Visitors to the site in question will be provided with a message telling them to complete the hcaptcha validation check to “secur” the security of their connection before proceeding further.

However, when the user clicks on the “I Am Human” checkbox for evaluation, he receives an error message saying “Captcha validation failed” and prompts him to click the button to proceed with “Alternative validation”.

Doing so will copy the command to the user’s clipboard and the victim will receive a series of instructions, depending on the operating system. You are guided to open the Windows Run dialog and run PowerShell commands on Windows, but it will be replaced by a shell script that is run by launching the terminal app on MacOS.

For that part, the shell script prompts the user to enter the system password and downloads the payload for the next stage, a known steeler known as the Atomic Stealer.

See also  Microsoft Discovery: How AI Agents Accelerate Scientific Discovery

“Insufficient logic at distribution sites, such as inter-platform indices of inconsistency, points to a hastily constructed infrastructure,” Pal said.

“The distribution page for this AMOS variant campaign issue contained inaccuracies in both programming and front-end logic. For Linux user agents, the PowerShell command was copied. Additionally, the instruction “hold Windows key + R” was displayed for both Windows and Mac users. ”

This disclosure comes amid the use of Clickfix tactics to surge in campaigns and provide a wide range of malware families over the past year.

“Actors who perform these target attacks usually use similar techniques, tools and procedures (TTP) to gain initial access,” Darktrace said. “These include providing malicious payloads to exploit spear phishing attacks, drive-by compromises, or to misuse trust in familiar online platforms such as GitHub.”

Links distributed using these vectors are usually directed to redirect end users to malicious URLs that display fake Captcha validation checks and try to complete them to deceive users to deceive users if they are led to run malicious commands to fix non-existent issues.

The end result of this effective social engineering method is that users can compromise their own systems and effectively bypass security controls.

One April 2025 incident analyzed by Darktrace uses Clickfix as an attack vector to dig deep into the target environment, perform lateral movements, and send system-related information to an external server via HTTP POST requests, and ultimately remove data data.

“Clickfix Baiting is a widely used tactic that threat actors leverage human error to bypass security defenses,” says Darktrace. “By tricking endpoint users to perform seemingly harmless and everyday actions, attackers gain initial access to systems that can access and scale sensitive data.”

Other Clickfix attacks use fake versions of other popular Captcha services, such as Google Recaptcha and CloudFlare Turnstile, to provide malware delivery under the guise of daily security checks.

See also  Empower users and protect against Genai data loss

These fake pages are “Pixel-Perfect copies” of legal counterparts, which can sometimes trick unsuspecting users into injected into actual hacked websites. Steelers like Lumma and Stealc, as well as full-fledged remote access trojans like Netsupport Rat, are part of the payload distributed via fake turnstyle pages.

“Modern Internet users are conditioned to click on spam checks, captures and security prompts on their websites as soon as possible,” said Daniel Kelley of Slashnext. “Attackers know that they will take advantage of this ‘validation fatigue’ and follow the steps presented when many users see it as everyday. ”

Share This Article
Facebook Twitter Copy Link
Previous Article War big code in June 2025 War big code in June 2025
Next Article FIDMarseille unveils 2025 lineup including Rita Azevedo Gomes’ ‘Fuck The Polis’ FIDMarseille unveils 2025 lineup including Rita Azevedo Gomes’ ‘Fuck The Polis’
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News

Musk’s decision to limit political spending leaves some Republicans cold

Musk’s decision to limit political spending leaves some Republicans cold

Elon Musk's pledge to retreat from campaign spending -- if…

June 2, 2025
GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

McKinnack Island, Mich. -- Republican Rep. Bill Huizenga is preparing…

June 2, 2025
'It betrays our values': Progressives grapple with deadly shooting

'It betrays our values': Progressives grapple with deadly shooting

Progressive is tackling that two people who worked at the…

June 2, 2025
Beshear, Khanna to headline Dem mayor summit in July

Beshear, Khanna to headline Dem mayor summit in July

Two potential 2028 presidential primary candidates will descend on Cleveland…

June 2, 2025
Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

24 hours after Sunday's announcement that former President Joe Biden…

June 2, 2025

You Might Also Like

Important 10-year-old round cube webmail bug allows authenticated users to execute malicious code
Technology

Important 10-year-old round cube webmail bug allows authenticated users to execute malicious code

2 Min Read
Why traditional DLP solutions fail in the browser era
Technology

Why traditional DLP solutions fail in the browser era

4 Min Read
DeepSeek-V3 unveiled: How hardware-enabled AI designs reduce costs and increase performance
Technology

DeepSeek-V3 unveiled: How hardware-enabled AI designs reduce costs and increase performance

9 Min Read
Google Chrome implements distrust and issues over two certificate authorities over compliance
Technology

Google Chrome implements distrust and issues over two certificate authorities over compliance

3 Min Read
newstrooper
newstrooper

Welcome to News Trooper, your reliable destination for global news that matters. In an age of information overload, we stand as a dedicated news platform committed to delivering timely, accurate, and insightful coverage of the world’s most significant events and trends.

  • Business
  • Entertainment
  • Gaming
  • Politics
  • Sports
  • Technology
  • Travel
  • World News
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2025 All Rights Reserved | Powered by News Trooper News

Welcome Back!

Sign in to your account

Lost your password?