Fake CleanMyMac Site Uses ClickFix Trick to Install SHub Stealer on macOS

2026-03-09T20:51:46Ze41ea41e8fbf036b43f1d0f52eba3c84b9184a2354d7b717acfe5389b3ee9d86
AI agentClickFixDatto RMMDindoorGPS exfiltrationGitHub compromiseGitHub secrets leakageHackerbot-ClawMuddyWaterRed Alert appSHub StealerSMS theftSocial Security scamTLS certificatescertificate leakscredential theftcrypto wallet theftfake CleanMyMacmacOSnation-state APTphishingprivate key exposurespywaresupply-chain attacktrojanized Android app

What happened

Feed reports multiple active threats and disclosures: a fake CleanMyMac site using a ClickFix browser trick to install SHub Stealer on macOS to harvest passwords and crypto wallets; Iran-linked MuddyWater deploying a new Dindoor backdoor against US and Israeli targets; an AI agent dubbed Hackerbot-Claw (Chaos Agent) abusing natural-language actions to compromise major GitHub repos and developer tooling; a large phishing campaign impersonating the U.S. Social Security Administration using fake tax docs and Datto RMM to hijack PCs; a trojanized Red Alert Android app spy targeting Israeli users (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
e41ea41e8fbf036b43f1d0f52eba3c84b9184a2354d7b717acfe5389b3ee9d86
Enrichment time
2026-03-09T20:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Fake CleanMyMac Site Uses ClickFix Trick to Install SHub Stealer on macOS · Baitaphish