Skip to main content
Mallory
Back to stories
credential-stealer-activitysearch-ad-manipulationloader-delivery-mechanismphishing-campaign-intelligence

ClickFix Campaigns Deliver MacSync Infostealer to macOS Users

Updated 9d agoFirst seen Mar 16, 202616 sources

Researchers reported three ClickFix campaigns that used social engineering rather than software exploitation to infect macOS users with the MacSync infostealer. The activity evolved over several months, beginning with fake sponsored search results for an OpenAI Atlas browser download hosted on fraudulent pages, then shifting to malicious workflows that abused shared ChatGPT conversations and GitHub-themed landing pages to make the infection chain appear legitimate. In each case, victims were instructed to open Terminal and paste commands, allowing the malware to be installed through user action instead of a traditional exploit.

The most recent campaign introduced a more advanced MacSync variant with multi-stage loaders, dynamic AppleScript payloads, and in-memory execution intended to improve evasion and persistence. Reporting indicates the later activity targeted users in Belgium, India, and parts of North and South America, while researchers said it remains unclear whether all three campaigns were conducted by the same threat actor. The findings underscore a broader trend of attackers adapting ClickFix lures for macOS, using trusted platforms, sponsored links, and fake AI-tool installers to steal credentials and other sensitive data while bypassing file-based defenses by persuading users to execute the attack themselves.

Share:
ClickFix Campaigns Deliver MacSync Infostealer to macOS Users
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

14 events from the earliest known activity through the most recent confirmed update.

14 EVENTS
Nov 1, 20257mo ago

ClickFix campaign uses fake OpenAI Atlas browser lure to deliver MacSync

In November 2025, researchers observed a ClickFix campaign targeting macOS users through sponsored Google search results and a fake Google Sites page advertising a bogus OpenAI Atlas browser. Victims were tricked into pasting obfuscated Terminal commands that installed the MacSync infostealer.

Dec 1, 20256mo ago

Jamf flags ClickFix lures distributing MacSync on macOS

In December 2025, Jamf Threat Labs previously identified ClickFix-style lures being used to distribute the MacSync infostealer to macOS users. This marked an early public indication that pastejacking-style social engineering had expanded to MacSync delivery.

MacSync campaign shifts to ChatGPT shared-conversation lures

By December 2025, attackers had evolved their macOS ClickFix activity to use malicious or weaponized ChatGPT shared conversation links and other AI-themed installation prompts. The campaign continued to rely on users manually executing Terminal commands rather than exploiting software flaws.

Feb 1, 20264mo ago

Latest ClickFix campaign adds GitHub-themed lures and in-memory execution

In February 2026, researchers observed the most advanced MacSync ClickFix campaign yet, using regionally targeted pages impersonating trusted platforms such as GitHub and multi-stage loaders. The updated MacSync variant added dynamic AppleScript payloads, in-memory execution, and tracking infrastructure to improve evasion and victim profiling.

Mar 12, 20262mo ago

Breakglass exposes BarkBlitz crypto-targeting MacSync campaign

On 2026-03-12, Breakglass Intelligence reported that the MacSync stealer, also tracked as BarkBlitz, had been active since at least November 2025 and was targeting cryptocurrency users through ClickFix-style fake Zoom, Trezor Suite, and Ledger lures. The report detailed recovered AppleScript payloads, three C2 domains, malware signed with a stolen Apple Developer ID, and a capability to backdoor Ledger Wallet and Ledger Live for later seed-phrase theft and transaction interception.

MacSync / BarkBlitz: A Five-Month macOS Stealer Campaign Targeting Crypto Users - Breakglass Intelligence - Breakglass Intelligence
Mar 16, 20262mo ago

Sophos discloses three MacSync ClickFix campaigns targeting macOS users

On March 16, 2026, Sophos publicly reported three distinct ClickFix campaigns observed from November 2025 through February 2026 that delivered the MacSync infostealer to macOS users. The disclosure highlighted a clear increase in attacker sophistication and the growing use of AI-themed and trusted-platform lures to steal credentials, files, keychain data, and cryptocurrency seed phrases.

Mar 17, 20262mo ago

Claude-themed ClickFix campaign targets developers with MacSync

By March 2026, a campaign dubbed Claude Fraud was using sponsored Google ads and fake Claude-related sites, including pages on claude.ai and Squarespace, to target developers and security professionals. On macOS, victims were induced to paste Terminal commands that installed MacSync, and the campaign was reported to have affected more than 15,600 victims overall.

Mar 18, 20262mo ago

MacSync delivery expands via SEO poisoning and fake verification pages

By early 2026, a separate macOS campaign used SEO poisoning around searches for PDF books to redirect users to fake verification pages that prompted malicious Terminal execution. The staged infection chain delivered an AppleScript-based MacSync stealer that exfiltrated credentials, browser data, wallets, SSH keys, cloud configs, and documents.

Mar 19, 20262mo ago

CIS warns MacSync campaign is impacting U.S. SLTT macOS users

On March 19, 2026, CIS CTI reported an ongoing ClickFix-driven MacSync stealer campaign affecting macOS users in U.S. State, Local, Tribal, and Territorial government organizations. The activity used SEO poisoning and fake CAPTCHA pages to trick victims into running Terminal commands, extending known MacSync tradecraft into a newly identified government-sector victim set.

MacSync Stealer Campaign Impacting U.S. SLTT macOS Users
Mar 25, 20262mo ago

Recorded Future links five ClickFix clusters to Windows and macOS malware delivery

On March 25, 2026, Recorded Future’s Insikt Group reported five distinct ClickFix activity clusters targeting Windows and macOS users through fake verification and brand-impersonation lures. The report said several clusters delivered NetSupport RAT, while a dual-platform/macOS cluster was assessed with high confidence to deliver the MacSync infostealer using a common four-stage execution chain.

ClickFix Campaigns Targeting Windows and macOS
Apr 3, 20262mo ago

Breakglass maps MacSync C2 APIs and exposes SOCKS5 proxy monetization

On 2026-04-03, Breakglass Intelligence reported a newly identified MacSync command-and-control server and documented 29 API endpoints exposing a mature malware-as-a-service platform. The analysis showed MacSync could convert infected Macs into rotating SOCKS5 residential proxies and noted that Apple Developer ID certificate GNJLS3UYZ4 was still valid and signing MacSync samples, helping them bypass Gatekeeper warnings.

MacSync Stealer Part 2: 29 API Endpoints, a SOCKS5 Proxy Business, and the Same Apple Developer ID Still Signing Malware - Breakglass Intelligence - Breakglass Intelligence
Apr 21, 202627d ago

Netskope identifies ClickFix campaign targeting Asia finance-sector macOS users

On 2026-04-21, Netskope Threat Labs disclosed an active ClickFix campaign targeting macOS users in Asia’s finance sector with an AppleScript-based infostealer that also has Windows-targeting capability. The campaign uses fake CAPTCHA prompts and a pasted curl command to steal credentials, Keychain data, browser and wallet information, and forces victims to enter their macOS password through a deceptive Apple-like prompt.

macOS ClickFix attacks deliver AppleScript stealers • The Register
May 1, 202617d ago

Lazarus uses Mach-O Man ClickFix lures to deploy macrasv2 on macOS

On 2026-05-01, SC Media reported that North Korea-linked Lazarus Group was targeting high-value fintech and cryptocurrency professionals on macOS with a ClickFix campaign using fake Teams, Zoom, and Google Meet pages. Victims were tricked into running Terminal commands that launched the Mach-O Man malware kit, which staged fake macOS apps, harvested credentials and host data, and deployed the macrasv2 stealer.

New Mach-O Man malware tapped by Lazarus in macOS-targeted ClickFix attacks | brief | SC Media
May 6, 202612d ago

Microsoft details three macOS ClickFix infostealer variants and Apple mitigations

On 2026-05-06, Microsoft reported an evolving macOS ClickFix campaign using fake troubleshooting and utility pages to trick users into pasting Terminal commands, documenting helper, loader, and script-install variants active from late January through April 2026. The report said the activity delivered SHub Stealer and related payloads, used persistence via LaunchAgents and LaunchDaemons, included Telegram-based C2 fallback, and noted Apple had updated XProtect and added Terminal paste-blocking protections in macOS 26.4 and later.

ClickFix campaign uses fake macOS utilities lures to deliver infostealers | Microsoft Security Blog
SOURCE COVERAGE

Sources

16 references tracked. Mallory keeps watching after this page renders.

16 SOURCESView all
HackreadNews
May 8, 2026

Fake macOS Troubleshooting Sites Used to Steal iCloud Data in ClickFix Scam

hackread.com

Open source
Cyber Security NewsNews
May 7, 2026

New ClickFix Attack Targets macOS Users With Fake Disk Cleanup and Utility Lures - Cyber Security News

cybersecuritynews.com

Open source
Microsoft Security BlogAdvisories
May 6, 2026

ClickFix campaign uses fake macOS utilities lures to deliver infostealers | Microsoft Security Blog

microsoft.com

Open source
ScworldNews
May 1, 2026

New Mach-O Man malware tapped by Lazarus in macOS-targeted ClickFix attacks | brief | SC Media

scworld.com

Open source
Register SecurityNews
Apr 21, 2026

macOS ClickFix attacks deliver AppleScript stealers • The Register

go.theregister.com

Open source
Breakglass IntelNews
Apr 3, 2026

MacSync Stealer Part 2: 29 API Endpoints, a SOCKS5 Proxy Business, and the Same Apple Developer ID Still Signing Malware - Breakglass Intelligence - Breakglass Intelligence

intel.breakglass.tech

Open source
The Hacker NewsNews
Apr 1, 2026

Threat Intelligence - Latest News, Reports & Analysis | The Hacker News

thehackernews.com

Open source
Cert Hk Security AdvisoriesAdvisories
Mar 31, 2026

Phishing Alert - ClickFix Tactics Evolve, Now Attacking Both Windows and macOS

hkcert.org

Open source
Recorded Future BlogNews
Mar 25, 2026

ClickFix Campaigns Targeting Windows and macOS

recordedfuture.com

Open source
Cisecurity AlertsNews
Mar 19, 2026

MacSync Stealer Campaign Impacting U.S. SLTT macOS Users

cisecurity.org

Open source
Cloudsek BlogNews
Mar 18, 2026

MacSync Stealer: SEO Poisoning and ClickFix-Based macOS Malware Delivery Chain | CloudSEK

cloudsek.com

Open source
HackreadNews
Mar 17, 2026

ClickFix Attack Targets Devs with MacSync Malware via Fake Claude Tools

hackread.com

Open source
Security AffairsNews
Mar 17, 2026

From Windows to macOS: ClickFix attacks shift tactics with ChatGPT-based lures

securityaffairs.com

Open source
ScworldNews
Mar 16, 2026

ClickFix campaigns target macOS users via MacSync infostealer | news | SC Media

scworld.com

Open source
The Hacker NewsNews
Mar 16, 2026

ClickFix Campaigns Spread MacSync macOS Infostealer via Fake AI Tool Installers

thehackernews.com

Open source
Breakglass IntelNews
Mar 12, 2026

MacSync / BarkBlitz: A Five-Month macOS Stealer Campaign Targeting Crypto Users - Breakglass Intelligence - Breakglass Intelligence

intel.breakglass.tech

Open source
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

ClickFix Campaigns Deliver MacSync Infostealer to macOS Users | Mallory