macOS ClickFix Campaign Using Browser Fingerprinting Gate to Distribute Atomic Stealer (AMOS) and MacSync Infostealers — Threadlinqs Intelligence
As of 2026-08-05, macOS ClickFix Campaign Using Browser Fingerprinting Gate to Distribute Atomic Stealer (AMOS) and MacSync Infostealers is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 39 indicators of compromise.
Threat ID: TL-2026-1894 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Microsoft Threat Intelligence tracks an active macOS ClickFix campaign distributing Atomic Stealer (AMOS) and MacSync infostealers through 250+ algorithmically generated domains. The campaign evolved
Microsoft Threat Intelligence published a detailed analysis on August 5, 2026 documenting an active macOS ClickFix campaign that has undergone a significant operational security evolution. The campaign, first tracked in its current form since early 2026, distributes the Atomic macOS Stealer (AMOS) and MacSync infostealer families through a cluster of over 250 look-alike domains using algorithmically generated naming patterns (e.g., filecopperbasket[.]sbs, filevelvettractor[.]sbs, applefilevault[.]com).
The campaign's most notable evolution is the adoption of a server-side Traffic Distribution System (TDS) gate. Earlier iterations openly served the malicious ClickFix lure in page HTML, allowing scanners and crawlers to recover the full attack from page source. The current variant returns a minimal ~2.5 KB JavaScript profiling routine to all visitors. This routine collects environmental data from six browser objects (navigator, screen, window, document, location, console), performs WebGL GPU hardware validation to distinguish real Apple hardware from virtualized or emulated environments, checks timezone offset for data-center anomalies, detects iframe embedding, checks for touch-input support atypical on desktop macOS, and deploys anti-analysis probes including a toString() counter to detect open developer consoles and a prototype-tamper probe using canPlayType() to detect instrumented JavaScript environments. The fingerprint is silently submitted to the server with a mode: php tag; only visitors whose profile matches a genuine macOS browser on real Apple hardware receive the ClickFix lure page.
Qualifying targets receive a counterfeit Verified Publisher / Download for macOS page featuring GitHub-themed branding. The victim is instructed to open Terminal and run a command that downloads a multi-stage payload chain. In the AMOS variant (Helper Install campaign, active since January 2026), the first-stage script decodes Base64+Gzip content, downloads a Mach-O executable to /tmp/helper or /tmp/update, strips extended attributes (bypassing Gatekeeper), and launches it. The payload performs anti-VM checks using system_profiler for QEMU, VMware, and KVM indicators. It prompts for the macOS password and validates it via dscl . -authonly, storing the validated password in ~/.pass. AMOS then collects macOS Keychain databases, Chromium-based browser credentials/cookies/autofill, Apple Notes, cryptocurrency wallet data (browser extensions including MetaMask and Phantom, desktop wallets including Exodus and Electrum), and host system profile including IOPlatformUUID. Data is compressed to /tmp/out.zip via ditto and exfiltrated to a C2 /contact endpoint. AMOS establishes persistence via a LaunchDaemon at /Library/LaunchDaemons/com.finder.helper.plist running a .mainhelper backdoor that beacons to 45.94.47[.]204/api/tasks/ for remote command execution.
The MacSync variant (Loader Install campaign, active since February 2026) uses a similar curl-to-shell approach but delivers a multi-stage AppleScript infostealer executed entirely in memory via osascript. The loader first performs reconnaissance — checking keyboard locale, hostname, OS version, and external IP — and implements a Russian/CIS keyboard locale kill switch. The AppleScript payload harvests browser credentials, notes, media files, Telegram Desktop data, cryptocurrency wallets, keychain databases, and iCloud data. It specifically targets cryptocurrency hardware wallet applications (Ledger Live, Trezor Suite, Exodus) by downloading trojanized app.asar replacements from C2 infrastructure that inject seed-phrase exfiltration logic and re-sign with ad-hoc signatures to bypass macOS verification. Data is staged under /tmp/shub_<random ID>/, zipped, and exfiltrated. Persistence is achieved via a masqueraded Google Update agent at ~/Library/Application Support/Google/GoogleUpdate.app/ with a RunAtLoad plist.
A third variant (Script Install campaign, April 2026) executes entirely in memo
Target sectors: technology, cryptocurrency, finance
Target regions: North America, Europe, Asia, 005 - South America
Detections & IOCs
As of 2026-08-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 39 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
10 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566.002, T1204.002, T1059.004, T1059.002, T1059.007, T1106, T1543.001, T1543.004, T1027, T1036.005