Skip to content

Bad CAPTCHA in the wild tricks Mac users into installing malware through Terminal

Hackers have a new tool called ClickFix. The new attack vector combines fake human-verification prompts with malware, trying to trick users into running Terminal commands that bypass macOS security.

Silver MacBook with Apple logo closed on a gray desk mat, next to a black gadget resembling VR or ski goggles, with blurred colorful lights in the background
M5 MacBook Pro

The tactic, known as ClickFix, disguises malware delivery as a routine human verification step. Victims are instructed to open tools like Terminal or a command prompt and paste a command to complete verification.

Running the command installs malicious software on the system. Stolen data can include passwords, browser information, and cryptocurrency wallets.

Continue Reading on AppleInsider | Discuss on our Forums