Campaign record
macOS disk-cleanup lure sites
Fake macOS utility guides pushing Terminal ClickFix instructions
- Status as last assessed
- Active
- First seen
- 2026-01-31
- Last seen
- 2026-05-06
- Indicators
- 15
- Sources
- 1
- Targets
- macOS
- Fake macOS utility or troubleshooting guide
- Fake troubleshooting post on a publishing platform
Original research
- Microsoft Threat Intelligence2026-05-06Vendor researchFirst account
ClickFix campaign uses fake macOS utilities lures to deliver infostealers
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
Microsoft Threat Intelligence tracks macOS users being steered towards fake troubleshooting advice — disk-cleanup tips, cleaner utilities — published on standalone sites and on note-taking and blogging services. Each page carries an encoded blob the reader is told to paste into Terminal, which fetches and runs a script instead of installing anything. Three execution paths are separated in the report; all end in an infostealer that takes Keychain items, browser credentials, iCloud data, documents and wallet files, and two of them swap installed wallet applications for tampered copies. Because scripts launched from a shell are not put through the checks an application bundle would face, the operator gets execution without notarisation. This entry holds the lure sites and the hosts and file hashes the report leaves at the level of the operation rather than assigning to one path. Apple has since added a paste warning to Terminal.
Execution mechanisms
The only execution mechanism any published account describes for this campaign is Terminal paste (macOS) (T1059.004), which 8 of the 44 published campaigns in this corpus also record (18%).
Indicators
15 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator. No observation date is recorded for any of them.
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “macOS disk-cleanup lure sites”, campaign ID bb8d3f37, retrieved 2026-08-07, snapshot fb0eed7.
https://clickfixreport.com/campaigns/bb8d3f37/macos-fake-utility-clickfix
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.