ClickFix campaign uses fake macOS utilities lures to deliver infostealers
· Published 06/05/2026 21:35 · Modified 08/05/2026 09:19
Essential information
- Published
- 06/05/2026 21:35
- Modified
- 08/05/2026 09:19
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- applescript clickfix infostealer macos phantompulse shub stealer
- Tags
- 2026-05-06 applescript clickfix infostealer macos phantompulse shub stealer
- Related entities
- 1 vulnerabilities (cve), 145 indicators, 145 observables, 20 techniques (mitre), 4 malware, 117 others
Description
Threat actors are leveraging ClickFix-style social engineering tactics to distribute infostealers targeting macOS users through fake system utility lures. Attackers host malicious Terminal commands on blog sites and content platforms, disguised as troubleshooting advice for macOS issues. When executed, these commands download infostealers including Macsync, Shub Stealer, and AMOS, which exfiltrate browser credentials, cryptocurrency wallets, iCloud data, Keychain entries, and media files. The campaign has evolved to use Terminal-based script execution that bypasses Gatekeeper verification. Three distinct campaigns employ different tradecraft, with some replacing legitimate cryptocurrency wallet applications with trojanized versions and establishing persistence through LaunchAgents and LaunchDaemons that masquerade as legitimate services.
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Vulnerabilities (CVE) (1)
CVE-2026-31431
KEV
7.8
High
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 …
- Attack vector
- LOCAL
- Complexity
- LOW
- EPSS
- 0.0001 (P0.6%)
- Published
- 22/04/2026
- Modified
- 23/05/2026
Indicators (145)
-
dialerformac.com -
do2wers.com -
korovkamu.com -
seagalnssteavens.com -
ptrei.com -
biopranica.com -
https://zg5mkr7q.apexharvestor.digital -
bigbossbro777.com -
famiode.com -
https://qjywvkbl.degassing-mould.digital -
boso6ka.com -
isgilan.com -
avafex.com -
arkypc.com -
nitlebuf.com -
yygp4pdh.apexharvestor.digital -
futampako.com -
https://enslaveculprit.digital/script.sh -
tmcnex.com -
https://joytion.com/contact -
malext.com -
wewannaliveinpicede.com -
9d2da07aa6e7db3fbc36b36f0cfd74f78d5815f5ba55d0f0405cdd668bd13767 -
cauterizespray.icu -
raxelpak.com -
doqeers.com -
repqoow77wiqi.com -
ouilov.com -
joytion.com -
perewoisbb0.com -
522fdfaff44797b9180f36c654f77baf5cdeaab861bbf372ccfc1a5bd920d62e -
138.124.93.32 -
rvdownloads.com -
medoviypirog.com -
mentaorb.com -
https://avipstudios.com/contact -
hitkrul.com -
terafolt.com -
vagturk.com -
wewannaliveinpice.com -
milbiorb.com -
https://cauterizespray.icu/script.sh -
199.217.98.33 -
pewweepor092.com -
https://resilientlimb.icu/script.sh -
contatoplus.com -
kcbps.com -
woupp.com -
https://round5on.digital/script.sh -
reachnv.com -
trehlub.com -
https://laislivon.com/contact -
swift-sh.com -
wusetail.com -
joeyapple.com -
fastfilenext.com -
play67.cc -
lbarticle.com -
qjywvkbl.degassing-mould.digital -
coco-fun2.com -
thickentributary.digital -
rapidfilevault4.cyou -
pilautfile.com -
nibelined.com -
res2erch-sl0ut.com -
kayeart.com -
poeooeowwo777.com -
malkim.com -
kvrnjr30.apexharvestor.digital -
dryvecar.com -
jihiz.com -
45.94.47.204 -
pelorso90la.com -
https://www.iru.com/blog/atomic-stealer-amos-returns -
0x666.info -
uk176video.live -
round5on.digital -
92.246.136.14 -
aforvm.com -
rapidfilevault5.sbs -
metramon.com -
lakhov.com -
zg5mkr7q.apexharvestor.digital -
reews09weersus.com -
7ca42f1f23dbdc9427c9f135815bb74708a7494ea78df1fbc0fc348ba2a161ae -
haploadpin.com -
molokotarelka.com -
resilientlimb.icu -
https://thickentributary.digital/script.sh -
beltoxer.com -
rapidfilevault4.sbs -
168.100.9.122 -
kofeynayagush.com -
ejecen.com -
we2luck.com -
pipipoopochek6.com -
38.244.158.56 -
mikulatur.com -
avipstudios.com -
https://kvrnjr30.apexharvestor.digital -
us41web.live -
38.244.158.103 -
saramoftah.com -
raytherrien.com -
yablochnisok.com -
filefastdata.com -
miappl.com -
http://lakhov.com/contact -
honestly.ink -
xeebii.com -
stclegion.com -
bintail.com -
enslaveculprit.digital -
241a50befcf5c1aa6dab79664e2ba9cb373cc351cb9de9c3699fd2ecb2afab05 -
octopixeldate.com -
octopox.com -
res2erch-sl2ut.com -
hello-brothers777.com -
laislivon.com -
domenpozh.net -
paralegalmustang.icu -
https://yygp4pdh.apexharvestor.digital -
rawmrk.com -
vcopp.com -
persaniusdimonica8.com -
95.85.251.177 -
cleanmymacos.org -
mpasvw.com -
bankafolder.com -
boosterjuices.com -
coco2-hram.com -
pla7ina.cfd -
hilofet.com -
peloetwq71.com -
metlafounder.com -
https://mpasvw.com/contact -
benefasts-fhgs2.com -
http://paralegalmustang.icu/script.sh -
wriconsult.com -
rebidy.com -
pewqpeee888.com -
metrikcs.com -
stinarosen.com -
quantumdataserver5.homes -
rhymbil.com
Observables (145)
fastfilenext.comwe2luck.commilbiorb.comrebidy.comptrei.comrvdownloads.comlakhov.commentaorb.commedoviypirog.compilautfile.commalkim.comtrehlub.comhaploadpin.comboso6ka.comejecen.comhello-brothers777.comdialerformac.comkorovkamu.comavafex.compewqpeee888.comperewoisbb0.comthickentributary.digitalpewweepor092.compersaniusdimonica8.comenslaveculprit.digitalmetlafounder.commiappl.comraxelpak.commolokotarelka.comwusetail.commpasvw.compeloetwq71.complay67.ccuk176video.livewriconsult.comcleanmymacos.orghitkrul.comdo2wers.comraytherrien.comwewannaliveinpicede.comhonestly.inkouilov.compelorso90la.comlbarticle.compla7ina.cfdrapidfilevault4.sbsreachnv.comoctopox.combenefasts-fhgs2.comnibelined.commalext.comfamiode.comjihiz.comwoupp.comreews09weersus.comparalegalmustang.icutmcnex.comdoqeers.comres2erch-sl0ut.comjoeyapple.comquantumdataserver5.homespoeooeowwo777.comcauterizespray.icukayeart.comwewannaliveinpice.commetrikcs.comvagturk.comfilefastdata.comdryvecar.comjoytion.comterafolt.comavipstudios.comcoco-fun2.comarkypc.comoctopixeldate.comseagalnssteavens.combankafolder.comrapidfilevault5.sbsrawmrk.comswift-sh.comkcbps.comrhymbil.comdomenpozh.netkofeynayagush.comboosterjuices.comresilientlimb.icubeltoxer.comrepqoow77wiqi.commetramon.commikulatur.comyablochnisok.comfutampako.combintail.comcoco2-hram.combigbossbro777.comsaramoftah.comaforvm.comstinarosen.comround5on.digitalres2erch-sl2ut.com0x666.infovcopp.compipipoopochek6.combiopranica.comrapidfilevault4.cyoulaislivon.comstclegion.comcontatoplus.comxeebii.comus41web.livenitlebuf.comisgilan.comhilofet.comyygp4pdh.apexharvestor.digitalkvrnjr30.apexharvestor.digitalqjywvkbl.degassing-mould.digitalzg5mkr7q.apexharvestor.digital92.246.136.1445.94.47.20438.244.158.103199.217.98.3395.85.251.177168.100.9.122138.124.93.3238.244.158.56https://cauterizespray.icu/script.shhttps://yygp4pdh.apexharvestor.digitalhttps://resilientlimb.icu/script.shhttps://laislivon.com/contacthttps://joytion.com/contacthttp://lakhov.com/contacthttps://enslaveculprit.digital/script.shhttps://thickentributary.digital/script.shhttps://round5on.digital/script.shhttps://mpasvw.com/contacthttps://kvrnjr30.apexharvestor.digitalhttps://www.iru.com/blog/atomic-stealer-amos-returnshttps://avipstudios.com/contacthttps://qjywvkbl.degassing-mould.digitalhttp://paralegalmustang.icu/script.shhttps://zg5mkr7q.apexharvestor.digital9d2da07aa6e7db3fbc36b36f0cfd74f78d5815f5ba55d0f0405cdd668bd13767522fdfaff44797b9180f36c654f77baf5cdeaab861bbf372ccfc1a5bd920d62e7ca42f1f23dbdc9427c9f135815bb74708a7494ea78df1fbc0fc348ba2a161ae241a50befcf5c1aa6dab79664e2ba9cb373cc351cb9de9c3699fd2ecb2afab05
Techniques (MITRE) (20)
-
Masquerading
-
Credentials from Web Browsers
-
JavaScript
-
System Location Discovery
-
AppleScript
-
Credentials In Files
-
Launch Daemon
-
User Execution
-
Archive Collected Data
-
Launch Agent
-
Data from Local System
-
Obfuscated Files or Information
-
Hijack Execution Flow
-
Keychain
-
Steal Web Session Cookie
-
Account Discovery
-
Deobfuscate/Decode Files or Information
-
File and Directory Discovery
-
System Information Discovery
-
Exfiltration Over C2 Channel
Malware (4)
-
FamilyPublished 06/05/2026 19:35 · Modified 06/05/2026 19:35
-
FamilyPublished 06/05/2026 19:35 · Modified 06/05/2026 19:35
-
FamilyPublished 18/05/2026 17:52 · Modified 18/05/2026 17:52
-
FamilyPublished 18/05/2026 17:52 · Modified 18/05/2026 17:52
Others (117)
- dialerformac.com
- do2wers.com
- korovkamu.com
- seagalnssteavens.com
- ptrei.com
- biopranica.com
- bigbossbro777.com
- famiode.com
- boso6ka.com
- isgilan.com
- avafex.com
- arkypc.com
- nitlebuf.com
- yygp4pdh.apexharvestor.digital
- futampako.com
- tmcnex.com
- malext.com
- wewannaliveinpicede.com
- cauterizespray.icu
- raxelpak.com
- doqeers.com
- repqoow77wiqi.com
- ouilov.com
- joytion.com
- perewoisbb0.com
- rvdownloads.com
- medoviypirog.com
- mentaorb.com
- hitkrul.com
- terafolt.com
- vagturk.com
- wewannaliveinpice.com
- milbiorb.com
- pewweepor092.com
- contatoplus.com
- kcbps.com
- woupp.com
- reachnv.com
- trehlub.com
- swift-sh.com
- wusetail.com
- joeyapple.com
- fastfilenext.com
- play67.cc
- lbarticle.com
- qjywvkbl.degassing-mould.digital
- coco-fun2.com
- thickentributary.digital
- rapidfilevault4.cyou
- pilautfile.com
- nibelined.com
- res2erch-sl0ut.com
- kayeart.com
- poeooeowwo777.com
- malkim.com
- kvrnjr30.apexharvestor.digital
- dryvecar.com
- jihiz.com
- pelorso90la.com
- 0x666.info
- uk176video.live
- round5on.digital
- aforvm.com
- rapidfilevault5.sbs
- metramon.com
- lakhov.com
- zg5mkr7q.apexharvestor.digital
- reews09weersus.com
- haploadpin.com
- molokotarelka.com
- resilientlimb.icu
- beltoxer.com
- rapidfilevault4.sbs
- kofeynayagush.com
- ejecen.com
- we2luck.com
- pipipoopochek6.com
- mikulatur.com
- avipstudios.com
- us41web.live
- saramoftah.com
- raytherrien.com
- yablochnisok.com
- filefastdata.com
- miappl.com
- honestly.ink
- xeebii.com
- stclegion.com
- bintail.com
- enslaveculprit.digital
- octopixeldate.com
- octopox.com
- res2erch-sl2ut.com
- hello-brothers777.com
- laislivon.com
- domenpozh.net
- paralegalmustang.icu
- rawmrk.com
- vcopp.com
- persaniusdimonica8.com
- cleanmymacos.org
- mpasvw.com
- bankafolder.com
- boosterjuices.com
- coco2-hram.com
- pla7ina.cfd
- hilofet.com
- peloetwq71.com
- metlafounder.com
- benefasts-fhgs2.com
- wriconsult.com
- rebidy.com
- pewqpeee888.com
- metrikcs.com
- stinarosen.com
- quantumdataserver5.homes
- rhymbil.com