← All news

phishing

Fake CAPTCHAs Trick Mac Users Into Installing AMOS Stealer

2026-06-24

There is a new flavour of the ClickFix scam circulating, and this one has Mac users in its sights. Palo Alto Networks' Unit 42 has documented a campaign that uses a fake CAPTCHA page to convince visitors they need to 'verify' themselves by opening Terminal and pasting in a command. From there, the attacker does the rest.

The command pulls down a disk image from a server controlled by the attacker, mounts it using macOS's own hdiutil tool without surfacing anything in Finder, scans the contents for an app or installer, and launches it. The victim sees nothing out of the ordinary. What they have actually run is the Atomic macOS Stealer, better known as AMOS.

What AMOS takes

AMOS is not subtle about its appetite. It goes after:

  • Saved logins, cookies, autofill data and payment cards from eight Chromium-based browsers and several Firefox variants, including Tor and LibreWolf.
  • Telegram and Discord data, Apple Notes, Safari cookies and the macOS Keychain.
  • Any PDF, TXT or RTF files sitting in obvious places on disk.
  • Wallet data from Exodus, Electrum, Bitcoin Core, Binance, TonKeeper and others.

For extra mischief, it replaces legitimate Ledger Live and Trezor Suite installs with tampered versions, presumably so the operators can drain crypto holdings at a more convenient time. To capture the macOS account password, it pops up a convincing fake System Preferences prompt and waits for the user to type it in.

The cheap end of the effort spectrum

One of the domains seen in this run is svs-verificationdate[.]beer, which is a useful tell about the amount of effort attackers feel they need to put in when the social engineering is doing the heavy lifting. The technical work is modest. A fake CAPTCHA, a copy-pasteable command, a script that uses tools already on the machine. The hard part, getting a human to run it, is outsourced to the human.

That is the actual story here. macOS users have spent years being told that Mac malware is rare and that Gatekeeper has their back. Both of those things are still broadly true, and both of them are completely irrelevant the moment someone willingly types their password into a fake prompt because a website told them to.

The rule worth holding onto

No legitimate CAPTCHA, no real browser warning, no genuine system check will ever ask you to open Terminal and paste in a command. Not Cloudflare. Not Google. Not Apple. If a page tells you to, the page is lying to you. Close the tab.

The same applies to copy-paste instructions delivered through PowerShell prompts on Windows, which is where ClickFix started before it found its way over to macOS. Different operating system, same trick, same answer.

Fake CAPTCHAs Trick Mac Users Into Installing AMOS Stealer | RiskSense