Skip to content
May 31, 2026
  • Facebook
  • Twitter
  • Youtube
  • Linkedin
  • Instagram
  • Pinterest
Surekhabar

Surekhabar

News, Analysis & Updates

Trending News

Critical TP-Link Router Vulnerability CVE-2024-21833 Puts Networks at Risk Critical TP-Link Router Vulnerability CVE-2024-21833 Puts Networks at Risk 1
  • Cybersecurity

Critical TP-Link Router Vulnerability CVE-2024-21833 Puts Networks at Risk

April 19, 2026
Mirai Variant Nexcorium Exploits IoT Devices to Launch Large-Scale DDoS Attacks Mirai Variant Nexcorium Exploits IoT Devices to Launch Large-Scale DDoS Attacks 2
  • Cybersecurity

Mirai Variant Nexcorium Exploits IoT Devices to Launch Large-Scale DDoS Attacks

April 19, 2026
Samsung Launches AI-Powered Retail Tech with Glasses-Free 3D Screens in India Samsung AI Innovation 3
  • Tech

Samsung Launches AI-Powered Retail Tech with Glasses-Free 3D Screens in India

April 19, 2026
Microsoft Rolls Out KB5083769 Cumulative Update for Windows 11 Users Microsoft Rolls Out KB5083769 Cumulative Update for Windows 11 Users 4
  • Tech

Microsoft Rolls Out KB5083769 Cumulative Update for Windows 11 Users

April 15, 2026
Iran-Linked Hackers Expected to Continue Cyberattacks Despite Ceasefire Iran-Linked Hackers Expected to Continue Cyberattacks Despite Ceasefire 5
  • Tech

Iran-Linked Hackers Expected to Continue Cyberattacks Despite Ceasefire

April 15, 2026
Primary Menu
  • Home
  • Tech
  • Jobs
  • Tech

Hackers Target macOS with ClickFix Trick and NotNullOSX Malware

admin April 10, 2026
macos

A new macOS malware campaign is raising alarms among cybersecurity researchers, as attackers increasingly combine social engineering tactics with malicious files to bypass traditional security defenses and steal sensitive data from Apple devices.

Threat intelligence reports highlight the use of a technique known as ClickFix, where victims are tricked into executing malicious commands themselves rather than exploiting software vulnerabilities. The attack typically begins with a fake CAPTCHA or verification page that instructs users to copy and paste a command into the macOS Terminal, unknowingly initiating the infection process.

Once executed, the command downloads and installs malware such as NotNullOSX or similar infostealers via disguised files, including malicious DMG installers. These payloads are designed to appear legitimate while silently deploying background processes that evade detection and maintain persistence on the system.

Researchers note that this approach is particularly dangerous because it bypasses many traditional security mechanisms. Since the user manually runs the command, the attack avoids triggering typical exploit-based defenses and browser protections.

The malware’s capabilities are extensive. Once installed, it can harvest browser credentials, extract macOS Keychain data, access cryptocurrency wallets, and collect sensitive files such as developer secrets stored locally on the device. Stolen data is then exfiltrated to attacker-controlled servers, often without any visible signs to the victim.

Security experts warn that ClickFix campaigns, originally popular on Windows systems, are rapidly evolving to target macOS users, signaling a broader shift in attacker focus. The growing adoption of this method reflects a trend toward user-assisted attacks, where human interaction becomes the primary vulnerability rather than software flaws.

The rise of such campaigns also aligns with broader findings from threat intelligence reports, which show attackers increasingly leveraging simple but effective techniques to scale operations and bypass defenses. As these tactics become more widespread, even less sophisticated threat actors can deploy advanced malware with minimal technical effort.

Cybersecurity professionals are urging users to remain cautious, emphasizing that legitimate websites will never ask users to run Terminal commands for verification. Avoiding unknown downloads, especially DMG files from untrusted sources, and maintaining updated security protections are critical steps in defending against these evolving threats.

About The Author

admin

See author's posts

Post navigation

Previous: India Defers SIM-Binding Implementation to 2026 in Cybersecurity Push
Next: Critical Nginx Vulnerability CVE-2026-33032 Actively Exploited in the Wild

Related Stories

Samsung AI Innovation
  • Tech

Samsung Launches AI-Powered Retail Tech with Glasses-Free 3D Screens in India

admin April 19, 2026
Microsoft Rolls Out KB5083769 Cumulative Update for Windows 11 Users
  • Tech

Microsoft Rolls Out KB5083769 Cumulative Update for Windows 11 Users

admin April 15, 2026
Iran-Linked Hackers Expected to Continue Cyberattacks Despite Ceasefire
  • Tech

Iran-Linked Hackers Expected to Continue Cyberattacks Despite Ceasefire

Swa Tri April 15, 2026

Trending News

Critical TP-Link Router Vulnerability CVE-2024-21833 Puts Networks at Risk Critical TP-Link Router Vulnerability CVE-2024-21833 Puts Networks at Risk 1
  • Cybersecurity

Critical TP-Link Router Vulnerability CVE-2024-21833 Puts Networks at Risk

April 19, 2026
Mirai Variant Nexcorium Exploits IoT Devices to Launch Large-Scale DDoS Attacks Mirai Variant Nexcorium Exploits IoT Devices to Launch Large-Scale DDoS Attacks 2
  • Cybersecurity

Mirai Variant Nexcorium Exploits IoT Devices to Launch Large-Scale DDoS Attacks

April 19, 2026
Samsung Launches AI-Powered Retail Tech with Glasses-Free 3D Screens in India Samsung AI Innovation 3
  • Tech

Samsung Launches AI-Powered Retail Tech with Glasses-Free 3D Screens in India

April 19, 2026
Microsoft Rolls Out KB5083769 Cumulative Update for Windows 11 Users Microsoft Rolls Out KB5083769 Cumulative Update for Windows 11 Users 4
  • Tech

Microsoft Rolls Out KB5083769 Cumulative Update for Windows 11 Users

April 15, 2026
Iran-Linked Hackers Expected to Continue Cyberattacks Despite Ceasefire Iran-Linked Hackers Expected to Continue Cyberattacks Despite Ceasefire 5
  • Tech

Iran-Linked Hackers Expected to Continue Cyberattacks Despite Ceasefire

April 15, 2026

Connect with Us

  • Facebook
  • Twitter
  • Youtube
  • Linkedin
  • Instagram
  • Pinterest

About US

Surekhabar is a trusted digital news platform committed to delivering accurate, timely, and verified news. Our mission is to keep readers informed with facts that matter, presented clearly and responsibly.

Recent Posts

  • Critical TP-Link Router Vulnerability CVE-2024-21833 Puts Networks at Risk
  • Mirai Variant Nexcorium Exploits IoT Devices to Launch Large-Scale DDoS Attacks
  • Samsung Launches AI-Powered Retail Tech with Glasses-Free 3D Screens in India
  • Microsoft Rolls Out KB5083769 Cumulative Update for Windows 11 Users
  • Iran-Linked Hackers Expected to Continue Cyberattacks Despite Ceasefire

Categories

Cybersecurity Education Jobs Tech

Connect with Us

  • Facebook
  • Twitter
  • Youtube
  • Linkedin
  • Instagram
  • Pinterest
  • Facebook
  • Twitter
  • Youtube
  • Linkedin
  • Instagram
  • Pinterest
Copyright © All rights reserved. | MoreNews by AF themes.