None
EN
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
['The Hacker News', 'Swati Khandelwal', 'Aug']
The Hacker News
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks.
The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download.
The attack still requires the user to copy and run an obfuscated command in Terminal.
That command retrieves scripts and launches an infostealer targeting credentials, browser data, authentication stores, cryptocurrency wallets, and sensitive files.
A request resembling a genuine Mac in the expected context receives a GitHub-themed "Download for macOS" page with a forged "Verified Publisher" badge.