ClickFix macOS campaign and AMOS infostealer
🛡️ This post explains a macOS-focused variant of the ClickFix social-engineering attack that coerces users into pasting malicious commands into Terminal. The script downloads a hidden DMG, mounts it silently, and launches an installer that deploys the AMOS (Atomic macOS Stealer) malware. Once installed, the stealer harvests browser data, crypto wallets, desktop app credentials, Safari and Keychain data, and uploads it to attackers’ servers.
