← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 5, 2026 · 15:48via Microsoft Security Blog

From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

Brief

In this article

  • Activity overview
  • How ClickFix works
  • Campaign overview
  • ClickFix moved from open pages to fingerprinting gates
  • The fingerprinting gate
  • Mitigation and protection guidance
  • Indicators of compromise (IOC)
  • References
  • Learn more

Microsoft Threat Intelligence observed a macOS ClickFix campaign distributing infostealers, including MacSync and Atomic Stealer (AMOS) , through a large cluster of look-alike domains. The campaign evolved from broadly serving ClickFix lures to using a server-side browser-fingerprinting gate that shows the lure primarily to visitors whose environment appears consistent with a genuine macOS browser.

This cloaking limits visibility for crawlers, sandboxes, and some automated analysis workflows.

Read more on Microsoft Security Blog