ClickFix Campaigns Spread MacSync macOS Infostealer via Fake AI Tool Installers

Multiple ClickFix campaigns are distributing the MacSync macOS infostealer through fake AI tool installers, leveraging social engineering and malicious terminal commands.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region4 min read
MacSync macOS infostealer delivered through fake AI tool installers using ClickFix social engineering technique.

MacSync macOS infostealer delivered through fake AI tool installers using ClickFix social engineering technique.

Cybersecurity researchers have uncovered multiple ClickFix campaigns distributing a macOS information stealer known as MacSync, leveraging social engineering tactics rather than traditional exploit-based methods.

According to findings from Sophos, these attacks rely heavily on user interaction—specifically tricking victims into copying and executing malicious commands in the macOS Terminal.

Social Engineering Over Exploits

Unlike conventional malware delivery techniques, ClickFix campaigns depend entirely on deceiving users into running obfuscated commands.

Attackers exploit common developer behaviors, where command-line installation patterns such as “curl | sh” are widely trusted.

This makes the attack particularly effective against users who may not recognize the risks associated with executing unknown terminal commands.

Campaign Breakdown

Researchers identified three distinct campaigns delivering MacSync:

November 2025 Campaign

Attackers used a fake AI browser called “OpenAI Atlas,” promoted through malicious Google search ads.

Victims were redirected to a fake site hosted on Google Sites, where they were instructed to paste a command into Terminal. This action downloaded a shell script that requested system credentials and installed the MacSync malware.

December 2025 Campaign

A malvertising campaign targeted users searching for Mac optimization tips, redirecting them to fake conversations hosted on ChatGPT.

These conversations linked to GitHub-themed pages that tricked users into executing malicious commands.

February 2026 Campaign

The latest campaign targeted regions including Belgium, India, and the Americas, introducing a more advanced MacSync variant.

This version uses dynamic AppleScript payloads and executes entirely in memory, allowing it to evade detection and complicate forensic analysis.

Malware Capabilities

Once executed, the malicious script connects to a remote server to fetch the infostealer payload while simultaneously attempting to erase traces of its activity.

MacSync is capable of harvesting:

  • System credentials
  • Files and sensitive documents
  • macOS keychain data
  • Cryptocurrency wallet seed phrases

These capabilities make it a high-risk threat for both individuals and enterprise users.

Abuse of Trusted Platforms

Threat actors are increasingly abusing legitimate platforms such as:

These platforms are used to host malicious instructions disguised as legitimate software installation guides.

The tactic, sometimes referred to as InstallFix or GoogleFix, removes the need for traditional lures like fake CAPTCHAs or system alerts.

Expanding Threat Landscape

According to Pillar Security, over 20 malware campaigns targeting AI and developer tools were identified between February and March 2026.

These campaigns target:

  • AI coding tools
  • Browser extensions
  • Video generation platforms
  • Developer environments

macOS users are particularly targeted due to the higher likelihood of storing valuable credentials such as SSH keys, cloud tokens, and crypto wallets.

Cross-Platform Threat Evolution

Security researchers also observed similar infection chains deploying:

  • Alien Stealer on Windows
  • Atomic Stealer on macOS

According to Trend Micro, advanced campaigns are now incorporating techniques like:

  • PowerShell-based loaders
  • In-memory execution
  • Multi-stage infection chains

ClickFix Variants and TDS Abuse

A traffic distribution system known as KongTuke (also called 404 TDS) has been linked to ClickFix-style attacks.

This system leverages compromised WordPress sites to deliver malware such as ModeloRAT through fake CAPTCHA prompts and injected JavaScript.

These attacks often use DNS TXT records to stage malicious commands, making detection more difficult.

Widespread Campaign Activity

Recent research from Rapid7 indicates that over 250 compromised websites across 12 countries have been used to distribute ClickFix lures.

These include:

  • Regional news websites
  • Local business platforms

The campaigns ultimately deploy various infostealers, including StealC, Impure Stealer, and VodkaStealer.

Mitigation and Security Recommendations

To defend against ClickFix-style attacks, organizations and users should:

  • Avoid running unknown terminal or PowerShell commands
  • Verify sources before installing software
  • Use reputable security tools
  • Enable multi-factor authentication (MFA)
  • Keep systems and applications updated

Website administrators are also advised to secure WordPress installations by updating plugins, enforcing strong passwords, and monitoring for unauthorized access.

Final Insight

The rise of ClickFix campaigns highlights a significant shift in cyberattack strategies—moving away from exploiting software vulnerabilities toward manipulating user trust.

By disguising malicious commands as legitimate software installations, attackers are effectively bypassing traditional defenses and targeting human behavior as the weakest link.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.