Skip to content
September 9, 2026
  • Facebook
  • Twitter
  • Youtube
  • Linkedin
  • Instagram
  • Pinterest
Surekhabar

Surekhabar

News. Insights. Everything That Matters

Trending News

Microsoft Fixes 966 Vulnerabilities in Record-Breaking September Patch Tuesday Microsoft Fixes 966 Vulnerabilities in Record-Breaking September Patch Tuesday 1
  • Cybersecurity
  • Vulnerabilities

Microsoft Fixes 966 Vulnerabilities in Record-Breaking September Patch Tuesday

September 8, 2026
SSC CHSL Recruitment 2026: 2,536 Vacancies, Eligibility, Salary & Apply Online SSC CHSL Recruitment 2026 2
  • Government Jobs
  • Jobs
  • SSC Jobs

SSC CHSL Recruitment 2026: 2,536 Vacancies, Eligibility, Salary & Apply Online

September 8, 2026
Indian AI Startup Oppex AI Raises ₹4.2 Crore to Transform Industrial Operations Indian AI Startup Oppex AI Raises 3
  • Tech

Indian AI Startup Oppex AI Raises ₹4.2 Crore to Transform Industrial Operations

September 1, 2026
Unpatched iPhones Targeted by 13 Malicious Packages in Crypto Theft Campaign Sep 1, 2026, 09_11_26 PM 4
  • Cybersecurity

Unpatched iPhones Targeted by 13 Malicious Packages in Crypto Theft Campaign

September 1, 2026
Critical TP-Link Router Vulnerability CVE-2024-21833 Puts Networks at Risk Critical TP-Link Router Vulnerability CVE-2024-21833 Puts Networks at Risk 5
  • Cybersecurity

Critical TP-Link Router Vulnerability CVE-2024-21833 Puts Networks at Risk

April 19, 2026
Primary Menu
  • Home
  • Technology
  • Cybersecurity
    • CVE Records
  • Jobs
  • Tech

Hackers Target macOS with ClickFix Trick and NotNullOSX Malware

admin April 10, 2026
macos

A new macOS malware campaign is raising alarms among cybersecurity researchers, as attackers increasingly combine social engineering tactics with malicious files to bypass traditional security defenses and steal sensitive data from Apple devices.

Threat intelligence reports highlight the use of a technique known as ClickFix, where victims are tricked into executing malicious commands themselves rather than exploiting software vulnerabilities. The attack typically begins with a fake CAPTCHA or verification page that instructs users to copy and paste a command into the macOS Terminal, unknowingly initiating the infection process.

Once executed, the command downloads and installs malware such as NotNullOSX or similar infostealers via disguised files, including malicious DMG installers. These payloads are designed to appear legitimate while silently deploying background processes that evade detection and maintain persistence on the system.

Researchers note that this approach is particularly dangerous because it bypasses many traditional security mechanisms. Since the user manually runs the command, the attack avoids triggering typical exploit-based defenses and browser protections.

The malware’s capabilities are extensive. Once installed, it can harvest browser credentials, extract macOS Keychain data, access cryptocurrency wallets, and collect sensitive files such as developer secrets stored locally on the device. Stolen data is then exfiltrated to attacker-controlled servers, often without any visible signs to the victim.

Security experts warn that ClickFix campaigns, originally popular on Windows systems, are rapidly evolving to target macOS users, signaling a broader shift in attacker focus. The growing adoption of this method reflects a trend toward user-assisted attacks, where human interaction becomes the primary vulnerability rather than software flaws.

The rise of such campaigns also aligns with broader findings from threat intelligence reports, which show attackers increasingly leveraging simple but effective techniques to scale operations and bypass defenses. As these tactics become more widespread, even less sophisticated threat actors can deploy advanced malware with minimal technical effort.

Cybersecurity professionals are urging users to remain cautious, emphasizing that legitimate websites will never ask users to run Terminal commands for verification. Avoiding unknown downloads, especially DMG files from untrusted sources, and maintaining updated security protections are critical steps in defending against these evolving threats.

About The Author

admin

See author's posts

Post navigation

Previous: India Defers SIM-Binding Implementation to 2026 in Cybersecurity Push
Next: Critical Nginx Vulnerability CVE-2026-33032 Actively Exploited in the Wild

Related Stories

Indian AI Startup Oppex AI Raises
  • Tech

Indian AI Startup Oppex AI Raises ₹4.2 Crore to Transform Industrial Operations

admin September 1, 2026
Samsung AI Innovation
  • Tech

Samsung Launches AI-Powered Retail Tech with Glasses-Free 3D Screens in India

admin April 19, 2026
Microsoft Rolls Out KB5083769 Cumulative Update for Windows 11 Users
  • Tech

Microsoft Rolls Out KB5083769 Cumulative Update for Windows 11 Users

admin April 15, 2026

Trending News

Microsoft Fixes 966 Vulnerabilities in Record-Breaking September Patch Tuesday Microsoft Fixes 966 Vulnerabilities in Record-Breaking September Patch Tuesday 1
  • Cybersecurity
  • Vulnerabilities

Microsoft Fixes 966 Vulnerabilities in Record-Breaking September Patch Tuesday

September 8, 2026
SSC CHSL Recruitment 2026: 2,536 Vacancies, Eligibility, Salary & Apply Online SSC CHSL Recruitment 2026 2
  • Government Jobs
  • Jobs
  • SSC Jobs

SSC CHSL Recruitment 2026: 2,536 Vacancies, Eligibility, Salary & Apply Online

September 8, 2026
Indian AI Startup Oppex AI Raises ₹4.2 Crore to Transform Industrial Operations Indian AI Startup Oppex AI Raises 3
  • Tech

Indian AI Startup Oppex AI Raises ₹4.2 Crore to Transform Industrial Operations

September 1, 2026
Unpatched iPhones Targeted by 13 Malicious Packages in Crypto Theft Campaign Sep 1, 2026, 09_11_26 PM 4
  • Cybersecurity

Unpatched iPhones Targeted by 13 Malicious Packages in Crypto Theft Campaign

September 1, 2026
Critical TP-Link Router Vulnerability CVE-2024-21833 Puts Networks at Risk Critical TP-Link Router Vulnerability CVE-2024-21833 Puts Networks at Risk 5
  • Cybersecurity

Critical TP-Link Router Vulnerability CVE-2024-21833 Puts Networks at Risk

April 19, 2026

Connect with Us

  • Facebook
  • Twitter
  • Youtube
  • Linkedin
  • Instagram
  • Pinterest

About US

Surekhabar is a trusted digital news platform committed to delivering accurate, timely, and verified news. Our mission is to keep readers informed with facts that matter, presented clearly and responsibly.

Recent Posts

  • Microsoft Fixes 966 Vulnerabilities in Record-Breaking September Patch Tuesday
  • SSC CHSL Recruitment 2026: 2,536 Vacancies, Eligibility, Salary & Apply Online
  • Indian AI Startup Oppex AI Raises ₹4.2 Crore to Transform Industrial Operations
  • Unpatched iPhones Targeted by 13 Malicious Packages in Crypto Theft Campaign
  • Critical TP-Link Router Vulnerability CVE-2024-21833 Puts Networks at Risk

Categories

Cybersecurity Education Government Jobs Jobs SSC Jobs Tech Vulnerabilities

Connect with Us

  • Facebook
  • Twitter
  • Youtube
  • Linkedin
  • Instagram
  • Pinterest
  • Facebook
  • Twitter
  • Youtube
  • Linkedin
  • Instagram
  • Pinterest
Copyright © All rights reserved. | MoreNews by AF themes.