Atomic Stealer Campaign Uses 250+ Fake macOS Websites to Evade Detection

Cybersecurity researchers have uncovered a large-scale ClickFix campaign targeting macOS users through more than 250 fake websites. The attackers use browser fingerprinting to identify real macOS users before displaying a fake GitHub-style download page that tricks victims into pasting a malicious command into Terminal.

Atomic Stealer Campaign Uses 250+ Fake macOS Websites to Evade DetectionAtomic Stealer Campaign Uses 250+ Fake macOS Websites to Evade Detection

Once executed, the command downloads Atomic Stealer (AMOS), a powerful information-stealing malware capable of stealing browser passwords, cookies, authentication tokens, cryptocurrency wallet data, SSH keys, and sensitive files. Unlike traditional malware campaigns, this attack relies on social engineering rather than software vulnerabilities, making user awareness critical.

Security teams should monitor for suspicious Terminal activity involving curl, osascript, base64, or gunzip, educate users to never paste commands from websites into Terminal, and deploy behavior-based endpoint protection to detect evolving ClickFix attacks.


Protect your macOS devices from ClickFix attacks, phishing, and advanced malware with NPAV Total Security for Mac.