Jamf Threat Labs discovered a malicious ClickFix-style advertising campaign on X that impersonates the popular Mac utility DynamicLake to distribute Atomic Stealer malware to unsuspecting Apple computer users.
Key Points
- Attackers used a compromised verified account on X to promote a fake domain, dynamicmacisland[.]com, masquerading as the legitimate DynamicLake app.
- Victims were prompted to execute malicious code via the macOS Terminal, a common social engineering tactic known as ClickFix.
- The malware payload identified by Jamf includes variants of Atomic Stealer, specifically tracked as MacSync, and DigitStealer.
- Legitimate software developers, including the creator of DynamicLake, warn users to only download applications from official, verified websites.
- Jamf Threat Labs reported the malicious advertisement to X, which subsequently removed the content from its platform.