Updated
Updated · The Hacker News · Aug 7
Microsoft Tracks 250-Plus ClickFix Domains Fingerprinting Macs to Serve AMOS Lures
Updated
Updated · The Hacker News · Aug 7

Microsoft Tracks 250-Plus ClickFix Domains Fingerprinting Macs to Serve AMOS Lures

3 articles · Updated · The Hacker News · Aug 7

Summary

  • More than 250 front-end domains in a macOS ClickFix cluster now fingerprint each visitor server-side, letting operators show a fake “Download for macOS” page only to selected users while hiding it from crawlers and sandboxes.
  • A roughly 2.5 KB JavaScript gate checks MacIntel platform data, screen and WebGL signals, timezone, iframe status, touch support, open developer tools and even spoofed MP4 codec support before sending a mode:"php" bundle back to the server.
  • Qualified victims still must paste an obfuscated Terminal command, which pulls scripts from a /curl/ path and launches Atomic Stealer; Microsoft said the wider cluster has also delivered MacSync.
  • Microsoft did not disclose victim counts, targeted sectors or the operators, and said defenders should hunt the fingerprinting gate and shared staging infrastructure rather than disposable domains that can return benign pages on repeat visits.

Insights

Why are hackers quietly draining just one percent of macOS users' crypto wallets instead of emptying them completely?
How does a simple fake CAPTCHA trick macOS users into handing over their crypto and passwords without triggering Apple's security?