A Sophisticated Deception
Security researchers at CATO CTRL have uncovered a malicious campaign targeting macOS users by impersonating the legitimate OpenAI Codex platform. The attackers leveraged Google Sites and compromised advertising accounts to bypass standard security protocols and push a dangerous information-stealing payload.
How the Attack Unfolds
The operation relies on a clever abuse of trust signals. By utilizing Google Sites, the attackers host a landing page that appears authentic. To evade automated detection, the site itself remains clean, instead utilizing an iFrame to load malicious content from external servers.
The perpetrators utilized stolen, high-standing Google Ads accounts to ensure their fraudulent site appeared at the very top of search results for queries like "codex macos download." Because users naturally trust top-ranked Google search results, many were lured into the trap.
"The download and installation process was designed to look professional, mirroring the way various AI agents are installed via the macOS Terminal," note security experts.
The Role of the 'ClickFix' Technique
Upon visiting the deceptive site, users are presented with download options for both Windows and Mac. While the Windows button is merely a decoy, the Mac link initiates a process that prompts victims to execute a specific command in their Terminal application. This method, identified as a variation of a "ClickFix" attack, masks the malicious nature of the software by mimicking the legitimate installation procedures of real AI developer tools.
The Ultimate Threat: AMOS
Once the malicious command is executed, the system is compromised by AMOS (Atomic macOS Stealer). This sophisticated malware is specifically designed to exfiltrate highly sensitive information, including:
- Browser-stored login credentials and passwords
- Cryptocurrency wallet data
- Personal system information and sensitive documents
Security analysts warn that once installed, AMOS can strip a user of their digital identity in a matter of seconds, highlighting the importance of verifying the source of any software before running commands in the macOS Terminal.
