Threat Intelligence

Fake 'ClickFix' Sites Now Screen Visitors Before Delivering Mac Malware

The Hacker News · 6 Aug 2026
Key Takeaway Train staff to be suspicious of unexpected software download prompts, even on Mac devices, since these fake sites are specifically designed to evade automated security scans.

Microsoft Threat Intelligence has uncovered a large-scale campaign using more than 250 fraudulent websites to target Mac users with malware disguised as legitimate software. The scheme, known as ClickFix, has added a new layer of sophistication: before showing any malicious content, the sites now check visitors' browser details—a technique called fingerprinting—to determine whether they are a real person or an automated security tool.

This server-side filtering means that security researchers, web crawlers, and automated scanning systems are shown nothing suspicious, while selected everyday Mac users are served a convincing fake download prompt designed to trick them into installing malware. Because the malicious behaviour is hidden from most automated detection tools, the campaign can operate for longer periods without being flagged or taken down.

This evolution highlights how attackers are increasingly building evasion techniques directly into their infrastructure, making it harder for traditional security tools to catch these threats. For small businesses relying on Mac devices, this means standard antivirus scans may not always catch these lures, and staff awareness remains a critical line of defence.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.