New macOS ClickFix Attack Silently Mounts DMGs to Push Infostealer
A new macOS ClickFix attack uses deceptive Terminal commands to silently download, mount, and launch malicious DMG files containing the Atomic macOS Stealer (AMOS) infostealer malware. This malware targets numerous browsers, cryptocurrency wallets, messaging apps, and system keychains to steal sensitive information and uploads the data to attacker-controlled servers. The campaign begins with fake CAPTCHA pages tricking users into running commands that automate the infection process without manual DMG execution.






