Over 250 ClickFix Domains Employ Browser Fingerprinting to Conceal macOS Malware Lures
Over 250 ClickFix domains use browser fingerprinting to evade detection by hiding macOS malware lures from crawlers and sandboxes, while targeting genuine Mac users with forged software download pages. The attack employs technical checks like platform strings, timezone, and developer console detection to distinguish real users from automated analysis tools, requiring manual Terminal command execution for malware deployment.
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks.
The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download. Microsoft
*** END OF TRANSMISSION ***