Social Engineering

Apple Devices Under Attack: New ClickFix Campaign Delivers macOS Malware

macOS, Apple, ClickFix, apple malware, macos clickfix, apple clickfix, macOS ClickFix malware campaign explained, how ClickFix attacks infect Apple devices, macOS Malware, Malware
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: sdx15 / Shutterstock.com

A new macOS Malware campaign uses ClickFix social engineering and Terminal commands to silently download malicious files, steal passwords and compromise cryptocurrency data.

Security researchers from Palo Alto Networks Unit 42 have documented a new malware campaign targeting Apple operating systems. The attackers rely on a social engineering technique known as ClickFix. The method uses compromised websites that display fake CAPTCHA prompts or misleading system error messages to users. To complete the supposed verification process, victims are tricked into copying a provided command and pasting it into the macOS Terminal.

Ad

Once executed, the command uses the built-in system tool curl to silently download a malicious disk image (DMG) file from an external server and store it in the system’s temporary directory.

Malware silently deployed in the background on Apple devices

Unlike previous campaigns, where users had to manually open downloaded DMG files, the new Terminal command fully automates the process. The script uses the native macOS command hdiutil with the -nobrowse parameter. This mounts the disk image on the system without displaying an icon in Finder or on the desktop. The script then scans the directory structure for installation files and launches the discovered application using the open command. In the observed cases, the macOS malware disguises itself as an application called NNApp.app inside a self-signed application bundle downloaded from servers such as svs-verificationdate.beer.

Extensive data theft and manipulation of crypto applications

The delivered payload is a variant of the Atomic macOS Stealer (AMOS). Once active, the malware displays a fake password prompt designed to resemble the macOS system settings interface in order to capture the user’s administrator credentials. The malware is designed to extract sensitive information from eight Chromium-based browsers, including Google Chrome, Microsoft Edge and Brave Browser, as well as five Firefox-based browsers such as LibreWolf and Tor Browser. Stolen data includes cookies, saved passwords, credit card details and browser profiles.

Ad

The macOS malware also specifically searches for cryptocurrency wallet data, including wallets from Exodus Wallet, Electrum Wallet, Binance Wallet and Tonkeeper, as well as local documents, Apple Notes and Keychain databases. The collected information is compressed and transmitted to the attackers’ command-and-control servers. Particularly concerning is that the malware replaces existing legitimate installations of crypto applications such as Ledger Live and Trezor Suite with manipulated versions designed to directly steal digital assets.

(ll)

Ad

Weitere Artikel