Malware pages show blank screens to scanners, traps to Mac users

Microsoft tracked a macOS ClickFix network that fingerprints visitors before serving its stealer lures.

CSBadmin
2 Min Read

Microsoft researchers watched one macOS ClickFix operation change tactics in front of them. The same infrastructure that once served its malicious page openly now decides who gets to see it at all, hiding the lure behind a browser-fingerprinting check that most scanners fail.

More than 250 front-end domains take part, many built from the word “file” plus a dictionary term, such as filecopperbasket or applefilevault. In the older phase, the full attack sat in the page HTML, including the obfuscated shell command and staging address, so static analysis recovered everything. Now a compact JavaScript routine collects platform, screen, WebGL, timezone, iframe, and touch signals from each visitor, with extra probes for open developer tools and spoofed codec support, and submits the bundle tagged mode:php.

The server then picks a response. Crawlers, sandboxes, and out-of-profile visitors get a blank page, a fake browser extension, or a decoy business site. A visitor that looks like a genuine Mac gets a forged download page with a “Verified Publisher” badge and a one-click command that, when pasted into Terminal, retrieves further scripts and launches Atomic Stealer. The cluster has also distributed MacSync.

Analysts should shift their detection focus accordingly. Lure domains rotate quickly, so the durable signal is the profiling behavior itself, which shows up in traffic regardless of the site name. Elsewhere in the ClickFix wave, a Go stealer that empties cryptocurrency wallets has been traced to hosting from Aeza Group, a Russian provider sanctioned by the U.S., U.K., and Australia.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.