Codex ClickFix Malware: How Installation Lure Spreads AMOS Infostealer

www.news4hackers.com-codex-clickfix-malware-how-installation-lure-spreads-amos-infostealer-codex-clickfix-malware-how-installation-lure-spreads-amos-infostealer

A deceptive macOS installation page leveraging ClickFix methods and legitimate Google Sites domains has been identified as a delivery mechanism for a payload believed to be the Atomic macOS Stealer (AMOS), according to Cato Networks’ report released on Monday.

Discovery and Methodology

The fraudulent interface exploits iframe integration to manipulate malicious content without direct modification of the hosting Google Site or deployment of malicious assets on the platform. This architectural separation allows attackers to combine a verified domain with independently managed ClickFix components, enabling covert operations.

The Attack Chain

The macOS attack chain begins with a shell script acting as a loader, which contains an embedded binary blob decoded and executed via the eval command. This secondary payload initiates a connection to a remote server, transmitting system-specific data to establish a foothold. The final stage involves a Mach-O binary, exhibiting characteristics consistent with AMOS stealer variants observed in prior campaigns.

Infrastructure Configurations

Analysis revealed four distinct infrastructure configurations deployed across the campaign, each employing unique obfuscation strategies for the second-stage loader. Early iterations of the payload utilized base64-encoded compressed scripts, while later versions incorporate AES-encrypted gzip containers. Decryption keys in these advanced variants are reconstructed from dynamically generated variables, significantly complicating reverse engineering efforts.

Evasion Measures

Additional evasion measures include conditional content delivery: benign responses are served to non-macOS devices, and the /codex/ path hosts legitimate material while the malicious ClickFix interface operates under /codexx/. This OS- and path-sensitive gating mechanism creates operational ambiguity, potentially misleading automated analysis tools and human investigators. Requests failing to meet specific criteria—such as device type or URL path—may never trigger the malicious payload.

Trust as the Payload

The campaign’s reliance on Google’s infrastructure underscores a broader trend of adversaries exploiting trusted platforms to bypass traditional security controls. Researchers emphasized that “trust becomes the payload” in such scenarios, as no single component reliably exposes the attack lifecycle. Effective detection requires correlating multiple data points, including search traffic patterns, embedded content behavior, terminal execution logs, and outbound network activity.

Cato Networks noted that infrastructure elements associated with this Codex campaign have also been repurposed in Claude Code-themed attacks. However, those instances did not involve Google Sites hosting. The report highlights the evolving sophistication of macOS-targeted threats, emphasizing the need for layered defensive strategies against multi-stage, evasive payloads.

Conclusion

The report underscores the critical importance of proactive threat intelligence and multi-layered security measures to counteract increasingly sophisticated macOS-targeted campaigns like the Codex operation.


Blog Image

About Author

en_USEnglish