ClickFix macOS Infostealer Campaign Fake Utilities | MSSP Advisory

High
DateMay 6, 2026
📋Executive Summary
Threat actors are running a ClickFix campaign targeting macOS users with fake utility repair prompts that trick users into executing malicious Terminal commands. The attack bypasses traditional security controls by masquerading as legitimate system fixes, then harvests credentials, cryptocurrency wallets, and sensitive data. Microsoft reports this campaign specifically targets macOS environments through social engineering tactics that appear as helpful system utilities.
⚠️Why It Matters for MSSPs
Your Mac-using clients are vulnerable to credential theft that could compromise their entire environment, and stolen credentials often include business email, VPN access, and financial accounts that your security stack monitors. If a client gets compromised through this attack and you never warned them about fake macOS utility prompts, you failed your advisory obligation during an active campaign targeting their platform.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Phishing

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.