Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New ClickFix Attacks Exploit Official ChatGPT Website to Deliver macOS Infostealer

Infostealers have emerged as a significant cyber threat in 2025, affecting various operating systems and regions through advanced social engineering techniques.

Infostealers have emerged as a significant cyber threat in 2025, affecting various operating systems and regions through advanced social engineering techniques.

In a campaign identified by Kaspersky experts, a new method exploits user interest in OpenAI's Atlas browser. Attackers use the official ChatGPT website as a platform for hosting malicious installation guides.

The attack starts with paid search advertisements on Google. Users searching for "chatgpt atlas" encounter a sponsored result that seems to link to the official chatgpt.com domain, misleading users into clicking a malicious link.

Upon clicking, users are redirected to a shared ChatGPT conversation published through the platform's Share feature.

Attackers employ prompt engineering to craft a deceptive installation guide while concealing previous dialogue, minimizing suspicion.

This tactic preys on less technologically savvy users who may mistake it for legitimate instructions, not realizing it's public content rather than official documentation.

This approach reflects a trend of attackers exploiting legitimate services that permit content sharing on their domains.

Previous campaigns have similarly misused platforms like Dropbox, Google Docs, GitHub, GitLab, and Google Forms. Now, the capability to share AI chatbot conversations introduces another avenue for distributing harmful content while maintaining a semblance of credibility.

In a campaign identified by Kaspersky experts, a new method exploits user interest in OpenAI's Atlas browser.
Henry Dalton · Thehackingpost

The installation guide advises users to execute a single line of code in Terminal, a variant of the ClickFix attack technique.

The command downloads and executes a malicious script from atlas-extension.com.

Though many users are cautious about executing files from dubious sources, this approach conceals the true nature of the action, as users believe they are installing software rather than running code.

Upon execution, the script requests the system password, validating credentials by checking the "username + password" combination for executing system commands.

If incorrect, the prompt repeats; if correct, the script downloads and installs the malware payload.

Successful exploitation deploys AMOS (Atomic macOS Stealer), an advanced infostealer that collects extensive sensitive data, including passwords and cookies from Chrome, Firefox, and other browsers.

Advertisement

It also targets crypto wallets like Electrum, Coinomi, and Exodus, and applications such as Telegram Desktop and OpenVPN Connect.

Furthermore, the malware extracts files with TXT, PDF, and DOCX extensions from Desktop, Documents, Downloads folders, and the Notes application.

Besides data extraction, AMOS installs a persistent backdoor for automatic launch upon system reboot, providing attackers with remote control capabilities.

Users are advised to use reliable anti-malware software on all devices, especially macOS systems.

Commands from unsolicited sources should never be executed, regardless of their apparent legitimacy. Suspicious installation guides should be closed immediately or evaluated by an AI chatbot before proceeding.

This incident highlights that AI tools have become key targets for social engineering, necessitating increased vigilance from users unfamiliar with these technologies.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories