From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
Reported 05 Aug 2026 by otx · Severity: medium
Microsoft Threat Intelligence identified a macOS ClickFix operation distributing infostealers including MacSync and Atomic Stealer through over 250 algorithmically generated domains. The campaign evolved from openly displaying malicious content to implementing server-side browser