Bottom line: A ClickFix campaign with over 250 domains now uses browser fingerprinting to lock out security researchers and display a fake malware lure exclusively to genuine macOS users.
Microsoft Threat Intelligence has identified a ClickFix operation with more than 250 frontend domains that checks visitors via fingerprinting before delivering the malware lure. The server-side filtering significantly complicates detection by security researchers and automated analysis systems.
Microsoft Threat Intelligence has been observing the underlying infrastructure for several weeks already and has now documented a further evolution of the campaign: over 250 domains act as the front end for a ClickFix operation specifically targeting macOS users. New is a server-side gate that analyzes incoming requests via browser fingerprinting before deciding whether the visitor is even shown the malicious page.
The fingerprinting serves to distinguish crawlers, sandboxes, and automated analysis environments from genuine potential victims. If the gate detects characteristics of a security system or a bot, the actual malicious page remains hidden. Selected Mac users, on the other hand, are presented with a fake software download that uses typical ClickFix mechanics: victims are lured into executing malicious commands themselves, for example via supposed troubleshooting steps or installation instructions.
For defenders, this development means that classic automated detection via crawler-based URL scanning or sandbox analysis can fall short against this campaign, since the malicious infrastructure specifically locks out exactly such systems. The sheer number of over 250 domains also points to a substantial investment in infrastructure rotation, making takedown efforts more difficult.
CISOs with a significant share of macOS endpoints in their workforce should shift detection more toward behavior-based endpoint signals and user awareness training on ClickFix patterns, since network-side filter lists alone lose effectiveness due to the server-side cloaking. The indicators published by Microsoft should be fed into existing threat intelligence feeds where available.
Source: thehackernews.com · Published August 5, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.