Alert for a malware campaign in X ads targeting Mac users

  • Cybercriminals are using verified accounts on X to promote fake versions of the DynamicLake app.
  • The attack uses the 'ClickFix' technique, tricking users into running malicious commands in the macOS Terminal.
  • The installed software is a variant of Atomic Stealer, capable of stealing passwords, cookies, and cryptocurrency wallets.
  • Cybersecurity authorities recommend downloading apps only from the Mac App Store or official websites.

Malware in X ads for Mac

Browsing social media has become an everyday activity, but also an area where extreme caution is necessary. Recently, a sophisticated network of fraudulent advertisements On the X platform (formerly Twitter), which primarily targets Apple computer owners, what appears to be ordinary sponsored content may actually conceal code designed to compromise the security of the entire operating system.

This incident is not an isolated accident, but rather part of a growing trend where user trust in profiles with verification badges is exploited. The attackers have managed to make a malware distribution campaign It passed the social network's security filters, reaching thousands of people who, upon seeing an account with many followers and seemingly professional content, did not hesitate to click on the provided links.

Mac Virus
Related article:
Do I need antivirus software for my Mac?

The DynamicLake impersonation scam

DynamicLake Impersonation on Mac

The hook used by the criminals is the DynamicLake application, a well-known tool that allows users to emulate the iPhone's 'Dynamic Island' on MacBooks. The scammers have meticulously copied the design, logos, and promotional images of the real app to create a sense of absolute legitimacyHowever, the final destination of these ads is not the developer's official website, but domains with extremely similar names that seek to confuse the less attentive user.

Once the victim lands on the fraudulent website, they are prompted to download the program. The problem arises when, instead of a conventional installer, the page asks the user to open the Terminal tool on their Mac. According to experts at Jamf Threat Labs, this prompts them to manually execute a specific command to supposedly complete the installation, a practice that should under no circumstances be carried out if it comes from an unverified source.

Fake ChatGPT guide installs malware on Mac
Related article:
Fake ChatGPT guide that installs malware on Mac: here's how it works

What is the ClickFix technique and how does it work?

ClickFix technique on macOS

This deception method is known in the cybersecurity world as 'ClickFix'. It doesn't rely on brute-force attacks to break through computer defenses, but rather on pure social engineering. By displaying a message that simulates a technical error or the need for an update, attackers They manipulate the victim's perception so that she herself opens the door to the virus. It's an old trick with a new wrapper that's proving surprisingly effective.

Entering the suggested code in the Terminal actually triggers the silent download of a malicious agent. Once installed, this program displays no windows or alerts, but instead begins to... track all sensitive data stored on the hard drive. Reports indicate that this system has managed to evade even some of the most advanced automated security scans because it is run manually by the user.

MacSync malware that evades Gatekeeper on macOS
Related article:
MacSync malware bypasses Gatekeeper and jeopardizes macOS security

The claws of Atomic Stealer and data theft

Atomic Stealer Malware for Mac

The software installed after falling into the trap is a variant of the dangerous Atomic Stealer, also known in some circles as MacSync. This program is specifically designed to act as an 'infostealer,' that is, an information thief. Its potential for damage is enormous, as it can steal passwords saved in the browserSession cookies that allow access to accounts without a password and critical system files.

In addition to basic personal data, this campaign has focused particularly on the financial world. The malware is actively searching for it. cryptocurrency wallet keys and login credentials for banking platforms. Since it operates in the background without noticeably slowing down the computer, it can take the user days or weeks to realize that their information has been dumped on servers controlled by criminals, similar to how [the following] operates. North Korean malware targeting crypto companies on Mac.

Security on Mac against fraudulent ads

To stay safe from these threats, the wisest course of action is to be wary of any application that requires Terminal for installation. Within the Apple ecosystem, legitimate tools undergo a notarization process and, in the vast majority of cases, are distributed through the Mac App Store. This is crucial. Always check the website URL Before downloading anything, remember that no matter how verified a profile is on X, that doesn't guarantee that its advertising content is safe, since many times these accounts are rented or hacked for these campaigns.

Keeping your operating system updated and having active security solutions helps, but the best defense remains common sense when faced with overly enticing promises on social media. The original developer of the impersonated app has already issued statements regretting the misuse of its image, which underscores the importance of always go to primary sources to avoid unnecessary problems with the security of our personal devices.

App Store fraud: fake cryptocurrency apps
Related article:
App Store fraud with fake cryptocurrency apps: this is how the campaign that endangered your digital wallets operated

You might be interested in:
According to Apple, it is the most effective company in the world in security
Add as preferred source