New ClickFix Attacks Exploit Official ChatGPT Website to Deliver macOS Infostealer
Infostealers have emerged as a significant cyber threat in 2025, affecting various operating systems and regions through advanced social engineering techniques.
Infostealers have emerged as a significant cyber threat in 2025, affecting various operating systems and regions through advanced social engineering techniques.
In a campaign identified by Kaspersky experts, a new method exploits user interest in OpenAI's Atlas browser. Attackers use the official ChatGPT website as a platform for hosting malicious installation guides.
The attack starts with paid search advertisements on Google. Users searching for "chatgpt atlas" encounter a sponsored result that seems to link to the official chatgpt.com domain, misleading users into clicking a malicious link.
Upon clicking, users are redirected to a shared ChatGPT conversation published through the platform's Share feature.
Attackers employ prompt engineering to craft a deceptive installation guide while concealing previous dialogue, minimizing suspicion.
This tactic preys on less technologically savvy users who may mistake it for legitimate instructions, not realizing it's public content rather than official documentation.
This approach reflects a trend of attackers exploiting legitimate services that permit content sharing on their domains.
Previous campaigns have similarly misused platforms like Dropbox, Google Docs, GitHub, GitLab, and Google Forms. Now, the capability to share AI chatbot conversations introduces another avenue for distributing harmful content while maintaining a semblance of credibility.
In a campaign identified by Kaspersky experts, a new method exploits user interest in OpenAI's Atlas browser.
The installation guide advises users to execute a single line of code in Terminal, a variant of the ClickFix attack technique.
The command downloads and executes a malicious script from atlas-extension.com.
Though many users are cautious about executing files from dubious sources, this approach conceals the true nature of the action, as users believe they are installing software rather than running code.
Upon execution, the script requests the system password, validating credentials by checking the "username + password" combination for executing system commands.
If incorrect, the prompt repeats; if correct, the script downloads and installs the malware payload.
Successful exploitation deploys AMOS (Atomic macOS Stealer), an advanced infostealer that collects extensive sensitive data, including passwords and cookies from Chrome, Firefox, and other browsers.
It also targets crypto wallets like Electrum, Coinomi, and Exodus, and applications such as Telegram Desktop and OpenVPN Connect.
Furthermore, the malware extracts files with TXT, PDF, and DOCX extensions from Desktop, Documents, Downloads folders, and the Notes application.
Besides data extraction, AMOS installs a persistent backdoor for automatic launch upon system reboot, providing attackers with remote control capabilities.
Users are advised to use reliable anti-malware software on all devices, especially macOS systems.
Commands from unsolicited sources should never be executed, regardless of their apparent legitimacy. Suspicious installation guides should be closed immediately or evaluated by an AI chatbot before proceeding.
This incident highlights that AI tools have become key targets for social engineering, necessitating increased vigilance from users unfamiliar with these technologies.
Based on reporting by GBHackers.
