ClickFix campaign uses fake macOS utilities lures to deliver infostealers

Reported 06 May 2026 by otx · Severity: medium

Threat actors are leveraging ClickFix-style social engineering tactics to distribute infostealers targeting macOS users through fake system utility lures. Attackers host malicious Terminal commands on blog sites and content platforms, disguised as troubleshooting advice for macOS