macOS ClickFix Campaign Delivers AMOS and Other Infostealers: A DNS Deep Dive

Microsoft recently analyzed1 a ClickFix campaign targeting macOS users with three infostealers: Macsync, Shub Stealer, and AMOS. The threat actors abused blog sites and other user-driven content platforms to host malicious commands aimed at users searching for macOS-related help.

Microsoft identified1 140 network IoCs connected to the campaign. After extracting unique domains from subdomain IoCs and filtering out legitimate and currently inactive entities with the WhoisXML API MCP Server2, we analyzed 138 IoCs.

Using our homegrown tools to investigate the threat, we uncovered these findings:

  • 11 unique client IP addresses that communicated with 14 of the domain IoCs
  • Eight domain IoCs that appeared in seven typosquatting groups with 3–33 members each
  • Eight domain IoCs that were likely registered with malicious intent
  • 119 unique IP addresses potentially owned by victims that communicated with five of the IP IoCs
  • 691 email-connected domains, 14 of which were confirmed malicious
  • 141 additional IP addresses, all of which were confirmed malicious
  • Seven IP-connected domains, four of which were confirmed malicious
  • 322 string-connected domains, 29 of which were confirmed malicious

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://www.microsoft.com/en-us/security/blog/2026/05/06/clickfix-campaign-uses-fake-macos-utilities-lures-deliver-infostealers/
  • [2] https://main.whoisxmlapi.com/ai/mcp-server
Try our WhoisXML API for free
Get started