Macfinger ClickFix Campaign Targets macOS Users Via Compromised Websites
A campaign dubbed 'Macfinger ClickFix' is actively compromising legitimate websites to redirect macOS users to fake bot protection pages, employing social engineering to trick them into verification and exfiltrate data.

A newly identified cyber campaign, dubbed 'Macfinger ClickFix,' is actively targeting macOS users by injecting malicious scripts into legitimate websites. This campaign leverages a social engineering technique known as ClickFix, which presents users with fake bot protection pages. The primary goal is to trick unsuspecting users into performing verification steps, thereby facilitating data exfiltration and the download of further malware.
The "Macfinger ClickFix" campaign, distinct from older utilities, operates by first compromising legitimate web pages. Malicious JavaScript is then injected, which, upon a user's visit, redirects them to a fraudulent "bot protection" page. This page is designed to appear legitimate, often prompting the user to "verify" their status as a human, a common tactic to bypass automated detection and trick users into interacting with malicious elements.
Once a user lands on the fake verification page, the campaign initiates a fingerprinting process. This involves collecting information about the user's activity and system, which is then sent to command-and-control (C2) servers. The collected data can include details about the user's browser, operating system, and specific actions taken on the page. This information is crucial for the attackers to profile victims and tailor subsequent attacks.
Following the fingerprinting and data exfiltration, the campaign proceeds to download malware onto the victim's system. Analysis of network traffic reveals that malware files are retrieved from specific IP addresses, such as 45.150.33[.]128. The downloaded payloads include Bourne-Again shell scripts and Mach-O executable files compiled for both ARM64 and x86_64 architectures, indicating a focus on a wide range of macOS devices.
Post-infection, the compromised macOS systems engage in further communication with C2 infrastructure, primarily over TCP port 8133 to the IP address 95.163.153[.]80. This communication channel is used for ongoing command and control, allowing attackers to potentially execute further malicious actions, exfiltrate additional data, or deploy ransomware.
Indicators of compromise associated with the Macfinger ClickFix campaign include specific domain names like velvet-otter-glagceis[.]life for malicious scripts and C2 communication. The campaign utilizes various JavaScript files for initial infection and subsequent data collection, with distinct SHA-256 hashes identified for the malicious scripts and the downloaded Mach-O executables.
The campaign's reliance on injecting scripts into seemingly legitimate websites makes it particularly insidious. Users are less likely to suspect a threat when browsing familiar or trusted online resources. The social engineering aspect, combined with the technical sophistication of fingerprinting and multi-architecture malware delivery, presents a significant risk to macOS users.
While the campaign was documented earlier in September, the "Macfinger ClickFix" moniker and the specific technical details, including the observed C2 infrastructure and malware hashes, provide new insights into its operation. Security professionals are advised to monitor for the identified indicators and educate users about the risks of unsolicited verification prompts on websites.