ClickFix campaign delivers Mac malware via fake Apple page

2026-04-10T14:51:51Z5bc83404fa277f8c1e898f6dcebabf26f21dae7d7a45e1f8b97ae5789fac4b44
ai-in-the-middleai-securityapiiro-clichrome-dbscclickfixclient-side-encryptioncookie-theftdata-brokersdevice-bound-session-credentialsebpfgmail-e2eejamflead-generation-privacylittle-snitch-linuxmac-malwaremalvertisingpatch-tuesdaypayroll-fraudphishingscript-editorseo-poisoningsession-messengersocial-engineeringstorm-2755

What happened

This feed covers multiple security developments: Jamf researchers uncovered a ClickFix-style campaign targeting macOS users via a fake Apple-themed webpage that lures victims into running malicious Script Editor commands to install Mac malware. Microsoft reported a financially motivated group (tracked as Storm-2755) using SEO poisoning, malvertising and phishing to serve fake Office 365 pages that redirect payroll deposits to attacker-controlled accounts. Google launched Gmail client-side (E2EE) encryption on Android and iOS for eligible Enterprise customers, and Chrome introduced Device-Bound

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
5bc83404fa277f8c1e898f6dcebabf26f21dae7d7a45e1f8b97ae5789fac4b44
Enrichment time
2026-04-10T14:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ClickFix campaign delivers Mac malware via fake Apple page · Baitaphish