Microsoft observed a macOS ClickFix campaign that evolved from openly serving infostealer lures to hiding them behind a server-side fingerprinting gate, exposing the content primarily to qualifying macOS visitors. msft.it/6049aEBu1
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide | Microsoft Security Blog
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while giving defenders new hunting opportunities.
msft.it