cognitive cybersecurity intelligence

News and Analysis

Search

250+ macOS ClickFix Domains Use Browser Fingerprinting to Hide Atomic Stealer Attacks

250+ macOS ClickFix Domains Use Browser Fingerprinting to Hide Atomic Stealer Attacks

Atomic Stealer is being pushed at Mac users through websites that look harmless. A large ClickFix operation uses more than 250 look-alike domains to steer selected visitors toward a fake download page and a malicious Terminal command.

ClickFix is built on persuasion, not a software flaw. The pages pose as download checks, updates, or CAPTCHA-style verifications, then urge people to paste a command into Terminal to begin the attack.

Microsoft analysts identified this shift. They found that the infrastructure moved from openly displaying malicious instructions to testing each visitor before deciding whether to reveal them. This makes routine scanning less reliable.

The counterfeit ‘Download for macOS’ page served (Source – Microsoft)

Microsoft said in a report shared with Cyber Security News (CSN) that a domain that appears benign to a researcher can still serve a tailored lure to a real macOS browser, allowing Atomic Stealer, also called AMOS, to collect personal and business data.

250+ macOS ClickFix Domains

The operation is built around a broad set of algorithmically named websites. Many use the word “file” with ordinary dictionary terms, giving victims names that can look like cloud storage, download, or synchronization services.

Microsoft confirmed more than 250 ClickFix front-end domains during its tracking window. Several follow forms such as filecopperbasket, filevelvettractor, and fileoceanhammer, while others place “file” differently or leave it out.

A decoy page (Source – Microsoft)

A qualified visitor sees a counterfeit “Download for macOS” page styled with GitHub-themed branding.

The branding is spoofed and does not indicate a GitHub compromise, but it is designed to make the request to run a copied command feel safe.

Once executed, the one-line command retrieves a remote script through a /curl/<id> address.

Further scripts download and launch AMOS, which can take browser credentials, stored passwords, cryptocurrency wallet data, authentication material, and sensitive files before sending them out.

Earlier open-lure delivery (Source – Microsoft)

The tactic reflects the wider ClickFix attack trend on macOS, where criminals rely on user action instead of a conventional installer. It also shows why a page asking someone to paste text into Terminal should be treated as suspicious, regardless of how convincing the site looks.

Fingerprinting Gate Blocks Security Analysis

The newer gate collects details from the browser, screen, window, document, location, and console before quietly returning them to the server.

It checks claimed platform, browser settings, display measurements, language, and other signs of a normal Mac desktop session.

It also examines graphics information through WebGL, a browser feature normally used for visual rendering.

Server-side fingerprint evaluation and possible responses for selected and non-selected visitors (Source – Microsoft)

Time zone, touch capability, embedded-frame status, and developer-console behaviour can help the server spot virtual machines, automated tools, or research environments.

Visitors that fail the test may get a blank page, a parked-looking site, or a harmless decoy such as a browser extension or VPN landing page.

Those with a convincing macOS browser profile receive the poisoned download instructions, a split that complicates automated detection and mirrors earlier fake CAPTCHA campaigns.

The defenders should hunt for combined behaviour rather than depend on one domain pattern. Useful signs include self-submitting fingerprint forms, hidden data fields, the mode: “php” parameter, and the file-word naming pattern.

Organizations should remind staff that genuine downloads and verification pages do not require Terminal commands.

Microsoft Defender SmartScreen flagging a ClickFix webpage (Source – Microsoft)

Security teams should watch for Terminal sessions that quickly launch curl, base64, gunzip, or osascript after web browsing, and investigate unusual sequences that clear quarantine attributes or make files executable.

Network monitoring should focus on encoded or compressed downloads from new or low-reputation sites, especially /curl/<hex-id> paths, as well as access to keychains, browser credential stores, SSH keys, and wallet data.

Defenders can also take context from Terminal-based malware delivery and Atomic Stealer delivery changes when building detections.

On newer macOS versions, a warning can block pasting a potentially malicious command into Terminal.

That safeguard can interrupt this chain, but careful user decisions and behaviour-based monitoring remain important because attackers are already adapting the way they ask victims to run code.

Indicators of Compromise (IoCs):-

TypeIndicatorDescriptionDomainapplefilevault[.]comClickFix WebpageDomainapricotfilepoint[.]comClickFix WebpageDomainbananafastfile[.]comClickFix WebpageDomaincloudfilebridge[.]comClickFix WebpageDomainfilecedarwallet[.]online.ClickFix WebpageDomainfilecopperbasket[.]sbsClickFix WebpageDomainfilecrimsonsignal[.]onlineClickFix WebpageDomainfilemarblegarden[.]sbsClickFix WebpageDomainfileoceanhammer[.]sbsClickFix WebpageDomainfilerubyfolder[.]sbsClickFix WebpageDomainfilevelvettractor[.]sbsClickFix WebpageDomainlemonfilewave[.]comClickFix WebpageDomainlimefilescope[.]comClickFix WebpageDomainmangocloudfile[.]comClickFix WebpageDomainorangesmartfile[.]comClickFix WebpageDomainsyncdatavault[.]comClickFix WebpageDomaincloudsendhub[.]comClickFix Webpage

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
The post 250+ macOS ClickFix Domains Use Browser Fingerprinting to Hide Atomic Stealer Attacks appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts