Affected Systems

macOS users targeted via 250+ algorithmically generated domains (e.g., filecopperbasket, apricotfilepoint[.]com). Campaign delivers MacSync and Atomic Stealer (AMOS) infostealers. All macOS versions susceptible to social engineering technique.

Exploitation Status

Active campaign confirmed by Microsoft Threat Intelligence. Threat actors actively distributing infostealers through server-side fingerprinting gates that selectively serve malicious Terminal commands to macOS browsers while showing decoy pages to sandboxes and non-macOS visitors.

Business Impact

Detection difficulty increased significantly. Traditional web crawlers, sandboxes, and automated analysis tools now receive benign decoy pages (fake VPN/browser extensions) instead of malicious lures, reducing visibility into active infrastructure. ClickFix technique bypasses macOS quarantine, code-signing, and notarization checks by executing via user-initiated Terminal commands rather than downloaded applications. Organizations with macOS endpoints face credential and data theft risk from MacSync and AMOS infostealers.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Hunt for domains matching pattern: dictionary words + 'file' token (e.g., file*basket, *filevault, *fastfile) and investigate DNS/proxy logs for connections to these naming conventions
  • Monitor macOS endpoint logs for Terminal execution of curl commands retrieving remote scripts, especially one-liners with obfuscation or piped to bash/sh
  • Block known IOCs: apricotfilepoint[.]com and related domains following filecopperbasket, filevelvettractor, fileoceanhammer, filemarblegarden naming patterns
  • Implement browser-based security controls that inspect server responses for fingerprinting behavior and conditional content delivery based on User-Agent strings
  • Educate macOS users on ClickFix social engineering: never paste Terminal commands from websites claiming to be download steps, CAPTCHAs, or verification processes