news.mlab.sh
Back to the feed
threat-intel

Macfinger ClickFix campaign, (Tue, Sep 22nd)

High
Summary

The Macfinger ClickFix campaign is a social engineering attack targeting macOS users through injected scripts on legitimate websites. The campaign uses fingerprinting to identify vulnerable systems and then delivers a series of malicious payloads, including a variant of the AMOS Stealer. The campaign involves a complex process of data collection, including user information and credentials, and utilizes a sophisticated ClickFix technique to deliver its payload. This campaign is relatively new and primarily targets macOS environments.

The Ransom-ISAC Blog recently documented a campaign targeting macOS environments using the ClickFix social engineering technique. I've been tracking this activity, which I’m now calling the ‘Macfinger ClickFix’ campaign. This isn't related to the MacFinger utility from decades ago – think of it as a modern equivalent of James Bond’s Goldfinger, but with macOS malware and the internet instead of Miss Galore.

I found several legitimate websites with injected scripts that are part of this campaign. Shown above are examples of the injected scripts and the fake bot protection page they generate. The campaign involves a complex process of data collection, including user information and credentials, and utilizes a sophisticated ClickFix technique to deliver its payload.

While displaying the fake bot protection page with the verification instructions, the Macfinger domain receives frequent POST requests from the victim host. These reports information on the user and track the user actions. For example, a POST request through HTTPS traffic shows the user abandoning the page without following the instructions.

According to the Ransom-ISAC Blog, this campaign is linked to a variant of Atomic macOS (AMOS) Stealer. The indicators I’ve found don’t fully align with the AMOS Stealer activity I’ve previously reported from a different campaign, so this is a different variant. The campaign relies on a series of malicious payloads delivered through a sophisticated ClickFix technique.

For mitigation and protection against Macfinger and other ClickFix campaigns, see guidance from the Microsoft Security Blog. Macfinger ClickFix seems like a fairly widespread campaign, but I haven't found much about it because 1) it seems relatively new and 2) it's only targeting macOS hosts.

Bradley Duncan brad [at] malware-traffic-analysis.net

Read the full article at SANS Internet Storm Center