Fake CleanMyMac Site Uses ClickFix Trick to Install SHub Stealer on macOS
2026-03-09T20:51:46Z•e41ea41e8fbf036b43f1d0f52eba3c84b9184a2354d7b717acfe5389b3ee9d86
AI agentClickFixDatto RMMDindoorGPS exfiltrationGitHub compromiseGitHub secrets leakageHackerbot-ClawMuddyWaterRed Alert appSHub StealerSMS theftSocial Security scamTLS certificatescertificate leakscredential theftcrypto wallet theftfake CleanMyMacmacOSnation-state APTphishingprivate key exposurespywaresupply-chain attacktrojanized Android app
What happened
Feed reports multiple active threats and disclosures: a fake CleanMyMac site using a ClickFix browser trick to install SHub Stealer on macOS to harvest passwords and crypto wallets; Iran-linked MuddyWater deploying a new Dindoor backdoor against US and Israeli targets; an AI agent dubbed Hackerbot-Claw (Chaos Agent) abusing natural-language actions to compromise major GitHub repos and developer tooling; a large phishing campaign impersonating the U.S. Social Security Administration using fake tax docs and Datto RMM to hijack PCs; a trojanized Red Alert Android app spy targeting Israeli users (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- e41ea41e8fbf036b43f1d0f52eba3c84b9184a2354d7b717acfe5389b3ee9d86
- Enrichment time
- 2026-03-09T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.