ClickFix campaign delivers Mac malware via fake Apple page
2026-04-10T14:51:51Z•5bc83404fa277f8c1e898f6dcebabf26f21dae7d7a45e1f8b97ae5789fac4b44
ai-in-the-middleai-securityapiiro-clichrome-dbscclickfixclient-side-encryptioncookie-theftdata-brokersdevice-bound-session-credentialsebpfgmail-e2eejamflead-generation-privacylittle-snitch-linuxmac-malwaremalvertisingpatch-tuesdaypayroll-fraudphishingscript-editorseo-poisoningsession-messengersocial-engineeringstorm-2755
What happened
This feed covers multiple security developments: Jamf researchers uncovered a ClickFix-style campaign targeting macOS users via a fake Apple-themed webpage that lures victims into running malicious Script Editor commands to install Mac malware. Microsoft reported a financially motivated group (tracked as Storm-2755) using SEO poisoning, malvertising and phishing to serve fake Office 365 pages that redirect payroll deposits to attacker-controlled accounts. Google launched Gmail client-side (E2EE) encryption on Android and iOS for eligible Enterprise customers, and Chrome introduced Device-Bound
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 5bc83404fa277f8c1e898f6dcebabf26f21dae7d7a45e1f8b97ae5789fac4b44
- Enrichment time
- 2026-04-10T14:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.