Skip to content
79
Expert
Chimera Difficulty Score
a synthesis of Flesch-Kincaid, Coleman-Liau, SMOG, and Dale-Chall readability metrics
macOS ClickFix attacks deliver AppleScript stealers to snarf credentials, wallets Data from browsers, cryptocurrency wallets, 200+ extensions hoovered up A ClickFix campaign targeting macOS users delivers an AppleScript-based infostealer that collects credentials and live session cookies from 14 browsers, 16 cryptocurrency wallets, and more than 200 extensions. Netskope Threat Labs researcher Jan ...
This ClickFix campaign exemplifies the evolving sophistication of social engineering attacks, where technical exploitation is secondary to psychological manipulation. The strongest version of this narrative is that it demonstrates how even security-conscious users can be tricked into executing malicious commands through familiar interfaces like Spotlight and CAPTCHA prompts. The attackers leverage macOS’s own design elements—such as the system lock icon—to create a false sense of legitimacy, exp...