macOS ClickFix cyberattack hero image showing malicious code and AI imagery

New ClickFix Campaign Uses ChatGPT Atlas To Infect macOS

Category: Cybersecurity

The latest ClickFix campaign targets macOS users by piggybacking on ChatGPT’s official website. Attackers created believable shared-chat pages that look like legitimate OpenAI content and paired them with paid Google ads for a fake product called ChatGPT Atlas. Victims are tricked into running a terminal command that secretly installs the Atomic macOS Stealer (AMOS) infostealer with elevated privileges. The operation blends social engineering, search advertising, and macOS password harvesting to create a high-impact threat.

Relevant Source (Kaspersky): The AMOS infostealer is piggybacking ChatGPT’s chat-sharing feature
Kaspersky details how paid Google ads and shared ChatGPT pages are abused to trick macOS users into running terminal commands that install the AMOS infostealer via a ClickFix-style workflow.

Quick Facts

  • Attackers abuse ChatGPT’s public share feature to host fake installation guides.
  • Google ads promote the nonexistent “ChatGPT Atlas for macOS” to drive traffic.
  • Instructions direct users to run a terminal command that installs AMOS malware.
  • Atomic macOS Stealer (AMOS) steals passwords, cookies, browser data, and crypto wallet files.
  • The malware collects documents and creates a persistent backdoor for access.
  • Kaspersky researchers attribute and document the campaign’s tactics.

How This Attack Works

The campaign hinges on shared ChatGPT conversations that look official because they live on the chatgpt.com/share path. Attackers used prompt engineering to make ChatGPT generate a polished installation guide for a fake Atlas browser, then removed the chat history and made the page public. Google ads direct users to these pages, where they are encouraged to run a downloaded command that pulls malware from an attacker-controlled server.

  • Pages appear to be legitimate OpenAI content.
  • Instructions mimic real macOS installation workflows.
  • The command retrieves and executes a malicious script.

The shared chat format lowers user suspicion because the domain is real even though the content is not.

Relevant Source (Kroll): New AMOS Infection Vector Highlights Risks around AI Adoption
Kroll describes how AMOS is delivered through trusted ChatGPT guidance that convinces macOS users to run terminal commands, closely mirroring this campaign’s use of realistic AI-generated instructions on legitimate ChatGPT pages.

Why Trusted Links Fail

This attack works because users trust the official ChatGPT domain. Social engineering improves dramatically when malicious content lives under a real brand’s URL. The fake guide persuades users to bypass security habits and enter their macOS password, which hands full system control to AMOS.

  • Domain trust amplifies attack success rates.
  • Paid ads bypass natural search and put threats at the top of results.
  • Script execution grants immediate credential harvesting.
  • Crypto wallets become high-value targets for theft.
  • Persistence allows ongoing remote access long after installation.

Campaigns like this show how blended threats can bypass traditional user defenses.

Relevant Source (Microsoft Security): Think before you Click(Fix): Analyzing the ClickFix social engineering technique
Microsoft details how ClickFix lures users through trusted domains, malicious ads, and copy-paste commands to rapidly gain credentials and long-term access, mirroring the same trust abuse and blended techniques used in this AMOS campaign.

Immediate Response Steps

Users should avoid running terminal commands from shared chats or unofficial guides. Systems already exposed should be checked for unauthorized profiles, startup agents, and suspicious network activity tied to atlas-extension.com. Updating browsers, rotating passwords, and securing wallets reduce follow-on damage.

Steps to take:

  1. Verify any software installation against the developer’s real site.
  2. Remove unknown LaunchAgents or startup items.
  3. Change passwords stored in Chrome or Firefox.
  4. Scan for Atomic macOS Stealer (AMOS) indicators from trusted security tools.
  5. Revoke access to compromised crypto wallets.

Alerting others in your organization or household helps prevent further infections.

Relevant Source (CISA): Avoiding Social Engineering and Phishing Attacks
CISA outlines how users should verify sources, avoid unsolicited instructions, and check systems for unauthorized changes, which aligns directly with safe recovery steps for users exposed to AMOS through ClickFix-style guidance.

Trusted Platforms Under Attack

Attackers know that trust signals influence behavior, so they target legitimate platforms rather than building fake ones from scratch. Hosting malicious instructions on chatgpt.com/share blurs the line between official and user-generated content, which increases the odds of someone following unsafe commands. Search ads add another layer of credibility because they are often assumed to be vetted.

The ClickFix technique continues to evolve because it exploits the user rather than the operating system. macOS defenses remain effective against unsigned apps, but they cannot protect users who voluntarily run commands in Terminal and enter their password. Blended social engineering remains a strong vector and will likely stay active as long as attackers see returns.

Relevant Source (Huntress): AI-Poisoning & AMOS Stealer: How Trust Became the Biggest Mac Threat
Huntress describes how attackers abuse trusted AI platforms, SEO, and legitimate-looking workflows to deliver AMOS, directly supporting the point that trust signals and reputable domains are being weaponized against macOS users.

Verify ChatGPT Links First

This campaign highlights the need to verify software sources even when a link appears to come from a trusted site. Shared ChatGPT pages can look official but still carry harmful instructions. Users who rely on macOS for privacy and security should treat unexpected install guides, password prompts, or ads claiming to offer new ChatGPT tools as high-risk.

Relevant Source (Palo Alto Networks Unit 42): Stealers on the Rise: A Closer Look at a Growing macOS Threat Landscape
Unit 42 reviews Atomic macOS Stealer and related families that harvest credentials, documents, and wallets on macOS, reinforcing why users must verify software sources and treat unexpected prompts as high risk.

FAQ

Are the fake pages actually hosted on ChatGPT’s real domain?
Yes. Attackers used the public share feature, which generates pages under chatgpt.com/share.

Is ChatGPT itself compromised?
No. The platform is being misused to host misleading instructions, not breached.

Does macOS block the AMOS malware automatically?
Not reliably. The attack relies on the user manually running a command in Terminal.

What data does AMOS target?
Passwords, browser cookies, crypto wallets, documents, and other stored credentials.

How can users avoid ClickFix scams?
Install software only from verified developer sites and never run commands from shared chats or ads.

Malware Risks, Warning Signs, And How To Prevent It

JENI Systems And How We Help

JENI strengthens macOS stability by repairing core services that often get targeted after an intrusion. JENI operates locally with no tracking which protects privacy when a system has been exposed. The tool removes junk, rebuilds damaged components, and restores performance after security incidents.

How JENI Supports System Recovery

  • Repairs corrupted macOS services after malware tampering.
  • Produces clear HTML reports that help users confirm system health.
  • Runs fully local which avoids exposing sensitive data during cleanup.

JENI gives users a dependable way to stabilize their Mac once threats like Atomic macOS Stealer (AMOS) create persistence or damage system files. The repair steps help restore predictable behavior. The local processing model protects privacy and reduces risk during recovery. The goal is a stable system that users can trust again after security issues.

Published on December 11, 2025 at 10:18 AM by:

Geoffrey has decades of hands-on experience in IT, software development, and cybersecurity, bringing expert technical insight to every article. He holds two IT bachelor’s degrees, a business degree, and a master’s degree in Cybersecurity and Information Assurance.