Apple Thwarts 'ClickFix' Malware Targeting Mac Users with New macOS Safeguard
Microsoft has issued a warning regarding the expansion of 'ClickFix' malware attacks, which now specifically target macOS users seeking technical assistance or additional disk space. This social engineering scam tricks victims into copying and pasting malicious commands into the Terminal utility, often disguised as solutions for storage issues or fake troubleshooting guides on platforms like Medium. Once executed, the malware can spy on users, steal data from iCloud Keychains, and replace cryptocurrency wallet applications with attacker-controlled versions. The attack exploits the misconception that macOS is immune to viruses and bypasses built-in defenses by deceiving users into voluntarily installing the threat. However, Apple has introduced a new protection mechanism in macOS 26.4 to counter this specific delivery method. The update features warnings when users attempt to paste commands into Terminal, identifying potential malware threats. To avoid disrupting legitimate workflows for power users and developers, these alerts are suppressed during the first 24 hours of setup or if developer tools are detected, but they will always trigger for known malicious commands.
Wire timeline
Apple Thwarts 'ClickFix' Malware Targeting Mac Users with New macOS Safeguard
Microsoft has issued a warning regarding the expansion of 'ClickFix' malware attacks, which now specifically target macOS users seeking technical assistance or additional disk space. This social engineering scam tricks victims into copying and pasting malicious commands into the Terminal utility, often disguised as solutions for storage issues or fake troubleshooting guides on platforms like Medium. Once executed, the malware can spy on users, steal data from iCloud Keychains, and replace cryptocurrency wallet applications with attacker-controlled versions. The attack exploits the misconception that macOS is immune to viruses and bypasses built-in defenses by deceiving users into voluntarily installing the threat. However, Apple has introduced a new protection mechanism in macOS 26.4 to counter this specific delivery method. The update features warnings when users attempt to paste commands into Terminal, identifying potential malware threats. To avoid disrupting legitimate workflows for power users and developers, these alerts are suppressed during the first 24 hours of setup or if developer tools are detected, but they will always trigger for known malicious commands.
PCMag.com - Technology Product Reviews, News, Prices & Tips