Skip to content

Campaign record

macOS disk-cleanup lure sites

Fake macOS utility guides pushing Terminal ClickFix instructions

Status as last assessed
Active
First seen
2026-01-31
Last seen
2026-05-06
Indicators
15
Sources
1
Targets
macOS
  • Fake macOS utility or troubleshooting guide
  • Fake troubleshooting post on a publishing platform

Original research

This page summarises and structures that research; it is not a substitute for the original.

Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.

Summary

Microsoft Threat Intelligence tracks macOS users being steered towards fake troubleshooting advice — disk-cleanup tips, cleaner utilities — published on standalone sites and on note-taking and blogging services. Each page carries an encoded blob the reader is told to paste into Terminal, which fetches and runs a script instead of installing anything. Three execution paths are separated in the report; all end in an infostealer that takes Keychain items, browser credentials, iCloud data, documents and wallet files, and two of them swap installed wallet applications for tampered copies. Because scripts launched from a shell are not put through the checks an application bundle would face, the operator gets execution without notarisation. This entry holds the lure sites and the hosts and file hashes the report leaves at the level of the operation rather than assigning to one path. Apple has since added a paste warning to Terminal.

Execution mechanisms

The only execution mechanism any published account describes for this campaign is Terminal paste (macOS) (T1059.004), which 8 of the 44 published campaigns in this corpus also record (18%).

Indicators

15 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator. No observation date is recorded for any of them.

Indicators recorded for this campaign, shown defanged
IndicatorTypeRoleAssessmentReport an error
domain, shown defanged for safety: apple-mac-fix-hidden dot medium dot comdomainLure pageShared platformReport an error in domain record 4fe16d1f-a922-4fba-bbd7-c517d6683f8e
domain, shown defanged for safety: claudecodedoc dot squarespace dot comdomainLure pageShared platformReport an error in domain record 7a623b09-f0f1-493b-91a9-edd5619c8790
domain, shown defanged for safety: cleanmymacos dot orgdomainLure pageAttacker-controlledReport an error in domain record 2adfe48e-2653-47b7-9bf1-83d3c577f4d5
domain, shown defanged for safety: mac-storage-guide dot squarespace dot comdomainLure pageShared platformReport an error in domain record 17849c5e-609c-4c1b-ade2-e3edafa7ff47
domain, shown defanged for safety: macclean dot craft dot medomainLure pageShared platformReport an error in domain record 8f5c755b-b05f-4a69-a19d-b5d17587b68b
domain, shown defanged for safety: macos-disk-space dot medium dot comdomainLure pageShared platformReport an error in domain record 7c38aebc-fadf-4f0b-8f50-1ac7ab7bd808
domain, shown defanged for safety: aforvm dot comdomainPayload hostNot yet assessedReport an error in domain record f1773504-9648-462f-8e26-7b72fdbff5e8
domain, shown defanged for safety: malext dot comdomainPayload hostNot yet assessedReport an error in domain record bd7fcf93-c4d1-48c4-b063-2af5aef40129
domain, shown defanged for safety: ouilov dot comdomainPayload hostNot yet assessedReport an error in domain record 86fdd2f9-4cfb-4725-ac4f-bc6190c5feb3
domain, shown defanged for safety: rebidy dot comdomainPayload hostNot yet assessedReport an error in domain record abb6a01c-680a-43da-a48f-c8e333229273
domain, shown defanged for safety: wusetail dot comdomainPayload hostNot yet assessedReport an error in domain record f6f2107e-ca63-4efe-a329-e8db30152f86
sha256, shown defanged for safety: 241a50befcf5c1aa6dab79664e2ba9cb373cc351cb9de9c3699fd2ecb2afab05sha256SampleNot yet assessedReport an error in sha256 record 08c3b64b-6f7c-4aaa-ad72-e648430a5dbf
sha256, shown defanged for safety: 522fdfaff44797b9180f36c654f77baf5cdeaab861bbf372ccfc1a5bd920d62esha256SampleNot yet assessedReport an error in sha256 record d49e845d-c6eb-4f1d-9cb4-194b300850c8
sha256, shown defanged for safety: 7ca42f1f23dbdc9427c9f135815bb74708a7494ea78df1fbc0fc348ba2a161aesha256SampleNot yet assessedReport an error in sha256 record e542d799-b683-458b-90df-bed574ec5a27
sha256, shown defanged for safety: 9d2da07aa6e7db3fbc36b36f0cfd74f78d5815f5ba55d0f0405cdd668bd13767sha256SampleNot yet assessedReport an error in sha256 record 1fd0d91c-51b1-4cc6-a368-1009b2138453

“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.

Not on this record

This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.

Cite as

ClickFixReport, “macOS disk-cleanup lure sites”, campaign ID bb8d3f37, retrieved 2026-08-07, snapshot fb0eed7.

https://clickfixreport.com/campaigns/bb8d3f37/macos-fake-utility-clickfix

Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.