Fake Codex Download Uses Google Sites to Deliver macOS Malware
Fake OpenAI Codex download pages on Google Sites, pushed via sponsored search and ClickFix lures, deliver malware to macOS users.
Threat actors are hosting fake Codex download pages on Google Sites and promoting them through sponsored search results. Victims are walked through ClickFix social engineering that leads to malware installation on macOS systems. The campaign abuses trusted Google infrastructure and search ads to reach Mac users.
Novel macOS Infostealer AmnesiaStealer Spread via ClickFix
Novel macOS infostealer AmnesiaStealer spreads via ClickFix social engineering and lets attackers remotely control victims' browsers to steal cookie data.
Infosecurity Magazine reports on AmnesiaStealer, a novel macOS infostealer distributed through the ClickFix social engineering technique. The malware includes capabilities that let attackers take remote control of the victim's browser in order to steal cookie data. The novel remote-browser-control function distinguishes it from commodity macOS infostealers.