Netskope Threat Labs reports macOS ClickFix malware campaign
Netskope Threat Labs reported on July 18, 2026 that a macOS ClickFix campaign uses social engineering to trick users into installing an AppleScript-based information stealer and a persistent remote access trojan.
TL;DR
- Netskope Threat Labs said a macOS ClickFix campaign targets users through social engineering.
- The attack deploys an AppleScript-based information stealer.
- The campaign also installs a persistent remote access trojan.
Netskope Threat Labs said the campaign targets macOS users by relying on social engineering rather than exploiting native macOS protections directly. The report was cited by 9to5Mac on July 18, 2026.
According to the report summary cited by 9to5Mac, the malware chain includes an AppleScript-based information stealer. AppleScript is Apple's built-in scripting language for automating tasks on macOS.
The same campaign also installs a persistent remote access trojan, according to Netskope Threat Labs. A remote access trojan is malware that gives an attacker ongoing remote control of an infected device.
Related questions
- What did Netskope Threat Labs report about the macOS ClickFix campaign on July 18, 2026?
- What malware components does the macOS ClickFix campaign install on macOS devices?
- How does the macOS ClickFix campaign target users according to Netskope Threat Labs?
More from Technology
Related content
More articles and news tagged with: Netskope Threat Labs, Apple, macOS, ClickFix, AppleScript, 9to5Mac