ClickFix campaign targets macOS users with Atomic macOS Stealer through silent DMG mounting

A new scam-style malware campaign is tricking Mac users into pasting a Terminal command that silently installs a password and crypto-stealing program. Palo Alto Networks says the ClickFix attack uses a fake CAPTCHA to get victims to run a command that downloads a malicious DMG disk image, mounts it with macOS hdiutil without showing it in Finder, and launches Atomic macOS Stealer (AMOS). The malware steals browser credentials, cookies, Keychain data, Telegram and Discord data, documents, and cryptocurrency wallet information, and can replace Ledger Live and Trezor Suite with trojanized versions.
Why it matters: This can lead directly to stolen passwords, drained crypto wallets, and account takeover for Mac users who follow the fake verification prompt. Users should never paste commands into Terminal from websites, and organizations should warn users about ClickFix lures and watch for AMOS-related activity.

Sources

C'mon, just copy this text string and paste it into your macOS Terminal – it'll fix your computer, honest
2026.07.16 72% relevant
This covers the same underlying ClickFix-style social-engineering threat against macOS users, but adds a distinct stealer family called ClickLock, new details on Terminal-paste infection, use of compromised WordPress sites and Telegram infrastructure, victim counts across 33 countries, and a coercive password-prompt locker behavior.
New macOS ClickFix attack silently mounts DMGs to push infostealer
Lawrence Abrams 2026.06.23 100% relevant
This article establishes a distinct macOS-focused ClickFix campaign using silent DMG mounting to deliver Atomic macOS Stealer, with concrete delivery mechanics and theft targets.
← Back to all stories