Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
AI Summary
A macOS-focused threat operation leveraging over 250 front-end domains employs browser fingerprinting to selectively serve malware lures to genuine Mac users while evading crawlers and sandbox environments. The fingerprinting script collects navigator properties, screen dimensions, WebGL signals, timezone, iframe detection, touch support, developer console activity, and codec capability checks to determine if the visitor is a real Mac user. Qualified users are presented with a fake GitHub-themed 'Download for macOS' page that delivers the Atomic Stealer (AMOS) infostealer via an obfuscated Terminal command. The command retrieves additional scripts from a /curl/<id> endpoint and executes payloads that target credentials, browser data, authentication stores, cryptocurrency wallets, and sensitive files.
AI-extracted · verify before operational use