Microsoft Threat Intelligence

Microsoft Threat Intelligence

@msftsecintel · Twitter ·

Microsoft observed a macOS ClickFix campaign that evolved from openly serving infostealer lures to hiding them behind a server-side fingerprinting gate, exposing the content primarily to qualifying macOS visitors. https://msft.it/6017aEB0z The campaign distributes infostealers like MacSync and Atomic Stealer (AMOS) through a large cluster of look-alike domains, using fingerprinting to determine which macOS users receive the lure while presenting benign or decoy content to other visitors. The shift makes the campaign harder to observe through traditional automated collection, increasing the importance of infrastructure- and behavior-based hunting. Read the blog from the Microsoft Security Research team for hunting guidance, detections, and recommendations.