macOS users are facing a new, highly polished ClickFix campaign that abuses fake CAPTCHAs to execute Terminal commands, silently deploy Atomic macOS Stealer (AMOS), and systematically loot crypto wallets and browser‑stored credentials.
This evolution of ClickFix underscores how social engineering, not exploits, remains one of the most effective paths to full compromise on Apple devices.
Instead of asking users to select images or type characters, the page instructs them to copy a block of text, open Terminal on macOS, paste the command, and press Enter.
That single command initiates the full infection chain. The script downloads a DMG disk image from an attacker‑controlled server to the /tmp directory under a randomly generated filename.
It then mounts the DMG in a stealthy fashion no Finder window, no desktop icon making the activity invisible to the average user while the script searches for an embedded application or installer package and auto‑executes it.
One of the payloads observed in this campaign is AMOS (Atomic macOS Stealer), an infostealer already known from earlier ClickFix and ChatGPT‑themed macOS attacks.
After execution, AMOS presents a fake macOS authentication prompt designed to look like a standard system dialog, tricking users into entering their administrator password and granting the malware elevated privileges.
With those privileges, AMOS systematically exfiltrates high‑value data. It targets Chromium‑based and Firefox‑derived browsers to collect cookies, saved logins, autofill data, stored payment card details, and profile information, as well as local PDF, TXT, and RTF documents.
Kaspersky Researchers said that, the campaign, victims land on a malicious or compromised site that displays a convincing CAPTCHA‑style “proof‑of‑humanity” gate, claiming an additional verification step is required before content can be accessed.
The macOS ecosystem is not spared: Safari cookies, Apple Notes contents, and credentials stored in the native Keychain are all within scope.

Collected artifacts are bundled into a ZIP archive and uploaded to the attackers’ server, after which the malware can even swap legitimate Ledger and Trezor applications with trojanized versions to intercept hardware wallet operations.
macOS ClickFix Attacks Use Fake CAPTCHAs
ClickFix began as a Windows‑focused social engineering pattern, where users were instructed to paste commands into the Run dialog to “fix” browser issues or pass verification checks.
Over the last two years, researchers have documented multiple macOS‑specific variations, including campaigns that piggyback official‑looking ChatGPT guides and typo‑squatted “Spectrum” domains to deliver AMOS via similar user‑driven execution chains.
The stealer places special emphasis on crypto assets, enumerating and harvesting configuration and wallet data from desktop clients such as Exodus, Electrum, Atomic Wallet, Wasabi, Bitcoin Core, Litecoin Core, DashCore, Guarda, Binance Wallet, Dogecoin Wallet, and Tonkeeper, along with more than 200 crypto‑related browser extensions.
The newly reported fake CAPTCHA DMG‑mounting flow shows ClickFix has fully matured on macOS, combining native disk image handling, invisible mounts, and realistic system prompts to bypass user suspicion and OS friction.

Security vendors including Kaspersky, Broadcom, and CloudSEK now track these campaigns as part of a wider surge in macOS‑targeting infostealers and crypto‑focused crimeware.
Defending against this campaign is less about patching and more about discipline. Users should never paste or execute commands in Terminal solely because a website instructs them to do so, regardless of any CAPTCHA, identity check, or “browser fix” pretext.
Administrator passwords must only be entered when the requesting app is well‑understood and intentionally installed, not after opaque web‑driven workflows.
Enabling automatic macOS security updates remains critical, but researchers have noted that current versions may not consistently flag these malicious Terminal commands, meaning platform safeguards cannot be treated as a safety net for poor decisions.
$1M Data Breach Warranty is Genuine Protection?: Download 10 Point Free AI SOC Breach Warranty Guide





