ClickFix on macOS: how the Terminal-based attack works, and how to protect yourself | Kaspersky official blog
We break down how ClickFix works on macOS: why attackers trick users into running commands in Terminal, what data the malware steals, and how to protect your device.
AI Analysis
Technical Summary
The ClickFix attack on macOS uses social engineering to convince users to copy and run malicious commands in Terminal under the guise of CAPTCHA or verification checks. The command downloads a malicious DMG file to the /tmp folder, mounts it hidden from the user, and executes an embedded malware installer. The primary malware distributed is Atomic macOS Stealer, which harvests sensitive data from Chromium- and Firefox-based browsers, crypto wallets (desktop apps and browser extensions), Telegram and Discord desktop apps, and Apple ecosystem data such as Safari cookies and Apple Keychain passwords. It also tricks users into entering their macOS password via fake authentication prompts to escalate privileges. The stolen data is compressed and uploaded to attacker servers. Additionally, the malware replaces legitimate Ledger and Trezor wallet apps with malicious versions. The attack exploits user trust and the habit of following instructions, often bypassing macOS security warnings. No direct software vulnerability is exploited; the attack depends on social engineering.
Potential Impact
Successful exploitation results in the installation of a powerful infostealer that exfiltrates a wide range of sensitive user data including saved passwords, cookies, autofill data, credit card information, cryptocurrency wallet data, and messaging app data. The attackers gain access to credentials and digital assets, enabling further account compromise, financial theft, and follow-on attacks. The malware also replaces legitimate hardware wallet software with malicious versions, increasing risk to cryptocurrency holdings. The attack compromises user privacy and security on macOS devices.
Mitigation Recommendations
No official patch or fix is available as this attack relies on social engineering rather than software vulnerabilities. Users should never paste commands into Terminal prompted by websites or untrusted sources. They should avoid entering their macOS administrator password unless they fully understand the requesting app. Regularly installing macOS security updates is recommended. Users should trust macOS security warnings and use reputable security software to detect and block malicious activity. Employing secure password managers and exercising caution with unknown websites can reduce risk.
ClickFix on macOS: how the Terminal-based attack works, and how to protect yourself | Kaspersky official blog
Description
We break down how ClickFix works on macOS: why attackers trick users into running commands in Terminal, what data the malware steals, and how to protect your device.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The ClickFix attack on macOS uses social engineering to convince users to copy and run malicious commands in Terminal under the guise of CAPTCHA or verification checks. The command downloads a malicious DMG file to the /tmp folder, mounts it hidden from the user, and executes an embedded malware installer. The primary malware distributed is Atomic macOS Stealer, which harvests sensitive data from Chromium- and Firefox-based browsers, crypto wallets (desktop apps and browser extensions), Telegram and Discord desktop apps, and Apple ecosystem data such as Safari cookies and Apple Keychain passwords. It also tricks users into entering their macOS password via fake authentication prompts to escalate privileges. The stolen data is compressed and uploaded to attacker servers. Additionally, the malware replaces legitimate Ledger and Trezor wallet apps with malicious versions. The attack exploits user trust and the habit of following instructions, often bypassing macOS security warnings. No direct software vulnerability is exploited; the attack depends on social engineering.
Potential Impact
Successful exploitation results in the installation of a powerful infostealer that exfiltrates a wide range of sensitive user data including saved passwords, cookies, autofill data, credit card information, cryptocurrency wallet data, and messaging app data. The attackers gain access to credentials and digital assets, enabling further account compromise, financial theft, and follow-on attacks. The malware also replaces legitimate hardware wallet software with malicious versions, increasing risk to cryptocurrency holdings. The attack compromises user privacy and security on macOS devices.
Defensive Guidance
No official patch or fix is available as this attack relies on social engineering rather than software vulnerabilities. Users should never paste commands into Terminal prompted by websites or untrusted sources. They should avoid entering their macOS administrator password unless they fully understand the requesting app. Regularly installing macOS security updates is recommended. Users should trust macOS security warnings and use reputable security software to detect and block malicious activity. Employing secure password managers and exercising caution with unknown websites can reduce risk.
Technical Details
- Article Source
- {"url":"https://www.kaspersky.com/blog/macos-clickfix-attack/56187/","fetched":true,"fetchedAt":"2026-07-27T19:33:20.278Z","wordCount":1839}
- Classification
- {"confidence":0.3,"severitySource":"heuristic","classifier":"rss-v2"}
Threat ID: 6a67b2809c2644c7f8b05e66
Added to database: 07/27/2026, 19:33:20 UTC
Last enriched: 07/30/2026, 15:48:55 UTC
Last updated: 09/09/2026, 09:12:02 UTC
Views: 144
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.