← Back to Tech & Science

Microsoft details sophisticated macOS campaign evading crawlers to deploy infostealers

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

REDMOND — Microsoft Threat Intelligence has identified a complex cyberattack campaign targeting Mac users that employs advanced evasion techniques to distribute malware while remaining invisible to automated security scanners. The operation, dubbed ClickFix by researchers at the technology giant, utilizes server-side browser fingerprinting and more than 250 domains to distinguish between human visitors and web crawlers.

Srinivasan Govindarajan, a senior security researcher at Microsoft, described the campaign as a significant evolution in macOS-targeted threats. The attackers deploy a mechanism that analyzes incoming traffic requests. When the system detects a request from an automated bot or a search engine crawler, it serves benign content to avoid detection and blacklisting by cybersecurity firms. However, when a real human user visits one of the compromised domains, the server delivers malicious payloads designed to trick victims into downloading infostealers.

The primary malware distributed through this campaign is AMOS, an information-stealing trojan capable of harvesting sensitive data such as passwords, credit card numbers, and session cookies from infected systems. The ClickFix operation relies on a network of over 250 domains that have been registered or compromised to host these deceptive landing pages. By hiding the malicious code behind server-side logic rather than client-side scripts, the attackers ensure that standard static analysis tools fail to identify the threat.

The campaign was detected and analyzed by Microsoft researchers as of August 5, 2026. The sophistication of the infrastructure suggests a well-resourced adversary capable of maintaining large-scale domain networks while dynamically adjusting content delivery based on visitor identity. This approach effectively bypasses traditional reputation-based defenses that rely on scanning websites for known malicious signatures.

Microsoft has not yet identified the specific threat actors behind the ClickFix campaign or their ultimate motivations. The group's decision to target macOS users with such a high degree of technical precision indicates a shift in focus toward platforms previously considered less vulnerable to mass-scale infostealer operations. Security experts note that the use of browser fingerprinting allows attackers to maintain a low profile while maximizing infection rates among genuine victims.

As Microsoft continues to monitor the infrastructure, questions remain regarding the full scope of data compromised and whether other malware families are being distributed through similar channels. The company is urging Mac users to exercise caution when visiting unfamiliar websites and to ensure their operating systems and security software are fully updated. With no attribution or stated motive released so far, investigators continue to track the movement of these domains as they evolve tactics to maintain access to victim machines.

Discussion

0 / 2000