Mac malware wave keeps using ClickFix trick, researchers report
9to5Mac's latest Security Bite roundup finds that ClickFix, a technique tricking victims into pasting Terminal commands themselves, has become the default delivery method for nearly all new Mac stealer malware since the Q1 2026 review. Researchers at Group-IB, Huntress, and Kaspersky have each identified new malware families—including ClickLock, a Go-based stealer, and a MacSync variant disguised as Homebrew—all using this same social-engineering approach. The report notes attackers are adding persistence, backdoors, and infrastructure hidden inside Apple's own services.
GoKawiil's interpretation of the reporting above, not reported fact.
The persistence of ClickFix despite Apple's macOS 26.4 Terminal prompt warnings suggests that user-driven social engineering remains harder to block than automated exploits, since it relies on tricking people rather than exploiting code flaws. The involvement of multiple independent security firms tracking similar campaigns could indicate a broader, coordinated shift in how Mac-targeting threat actors operate rather than isolated incidents.
- ClickFix has become the dominant delivery method for new Mac stealer malware, per multiple security researchers.
- Apple's macOS 26.4 Terminal prompt protections have not stopped attackers from using this technique.
- New malware families like ClickLock and a MacSync variant are adding persistence and hiding infrastructure within Apple's own services.
Malwarebytes Premium for Mac — With Mac stealer malware and ClickFix attacks becoming the dominant threat vector, having real-time anti-malware protection on your Mac is more important than ever. Malwarebytes Premium offers dedicated Mac malware detection and web protection to help block malicious downloads and phishing-style attacks before they compromise your system. It's a practical layer of defense to pair with good browsing habits.
See Malwarebytes Premium for Mac on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: 9to5mac.com — Arin Waichulis, 2026-09-28
Published there as: “Security Bite: Threat landscape review (September)”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.