From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
Brief
In this article
- Activity overview
- How ClickFix works
- Campaign overview
- ClickFix moved from open pages to fingerprinting gates
- The fingerprinting gate
- Mitigation and protection guidance
- Indicators of compromise (IOC)
- References
- Learn more
Microsoft Threat Intelligence observed a macOS ClickFix campaign distributing infostealers, including MacSync and Atomic Stealer (AMOS) , through a large cluster of look-alike domains. The campaign evolved from broadly serving ClickFix lures to using a server-side browser-fingerprinting gate that shows the lure primarily to visitors whose environment appears consistent with a genuine macOS browser.
This cloaking limits visibility for crawlers, sandboxes, and some automated analysis workflows.
