Fast Facts
- The Macfinger ClickFix campaign injects malicious scripts into legitimate websites, leading to fake bot protection pages that collect user data via frequent POST requests.
- It utilizes infected macOS-specific malware files—ranging from shell scripts to Mach-O executables—that communicate with command and control servers to exfiltrate user information and credentials.
- Indicators include persistent traffic to specific malicious domains and files linked to the initial shell script download and subsequent macOS malware, which differ from known variants like AMOS Stealer.
Threat Overview, Attack Techniques, and Targets
The Macfinger ClickFix campaign uses social engineering to infect macOS websites. Attackers inject malicious scripts into legitimate websites. These scripts cause a fake bot protection page to appear, prompting users with verification instructions. When users interact with the fake page, their information is sent via POST requests to the attacker’s server. The campaign specifically targets macOS environments and uses fingerprinting to identify macOS users. Once infected, the malware retrieves files from certain IP addresses, including malware and shell scripts. The malware operates as Mach-O executables on macOS, with one variant being an ARM64 executable and another x86_64. The campaign has indicators such as specific URLs (like velvet-otter-glagceis.life) and hashes of malicious files.
During infection, malicious traffic includes GET requests for malware payloads and POST requests reporting user data to command-and-control (C2) servers. The malware files are retrieved from IP addresses like 45.150.33.128 and communicate with C2 servers over TCP port 8133. This process helps the attacker gather user information and control infected hosts remotely.
Impact, Security Implications, and Remediation Guidance
The campaign is likely to lead to data theft and unauthorized control of infected macOS systems. Attackers collect user data through POST requests, which could include login credentials or other sensitive information. The injection of malware could also allow remote access to the infected device, leading to further compromise or malicious activities.
Security implications include the need to monitor for signs of injected scripts on legitimate websites, particularly those serving macOS users. Organizations and users should be cautious when encountering fake verification pages that generate POST traffic to malicious domains. Because this is a relatively new and macOS-specific campaign, specific remediation guidance is not provided here. Instead, affected parties should consult security advisories from relevant vendors and authorities, such as Microsoft Security Blog, to get updated defense strategies.
Expand Your Tech Knowledge
Explore the future of technology with our detailed insights on Artificial Intelligence.
Explore past and present digital transformations on the Internet Archive.
ThreatIntel-V1
