Skip to content
← All articles
Top Cybersecurity News·August 30, 2026·Cybersecurity PSA

From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

Voice options

Voice names come from your browser and device.

Microsoft Security Blog ↗
TL;DR
The fast version

In this article Activity overview How ClickFix works Campaign overview ClickFix moved from open pages to fingerprinting gates The fingerprinting gate Mitigation and protection guidance Indicators of compromise (IOC) References Learn more Microsoft Threat Intelligence observed a macOS ClickFix campaign distributing infostealers,…

Detailed briefing
Create a high-quality editorial cybersecurity illustration showing a macOS-style desktop browser environment facing a sophisticated cloaked web gate: an abstract glowing browser window is partially hidden behind layered translucent fingerprint patterns, device telemetry nodes, and a digital checkpoint that selectively reveals a deceptive prompt to a genuine-looking Mac visitor while shadowy crawler and sandbox icons are blocked outside. In the background, show a dark security operations workspace with analysts’ monitors, threat-hunting connections, domain graphs, and subtle indicators of phishing, stolen credentials, and downstream identity risk. Convey the evolution from a broad open lure into a targeted, evasive campaign using visual contrast between exposed web pages and a concealed gated pathway. Moody navy, charcoal, cyan, and amber palette, cinematic lighting, clean modern threat-intelligence aesthetic, realistic yet slightly conceptual, sharp details, strong depth, no readable text, no logos, no branding, no captions.

What happened

In this article Activity overview How ClickFix works Campaign overview ClickFix moved from open pages to fingerprinting gates The fingerprinting gate Mitigation and protection guidance Indicators of compromise (IOC) References Learn more Microsoft Threat…

The campaign evolved from broadly serving ClickFix lures to using a server-side browser-fingerprinting gate that shows the lure primarily to visitors whose environment appears consistent with a genuine macOS browser.

What is verified

This cloaking limits visibility for crawlers, sandboxes, and some automated analysis workflows.

The blog details the domain pattern, fingerprinting checks, infection chain, detection coverage, and hunting pivots that defenders can use to identify related activity.

Why it matters

A confirmed cyber incident can create secondary risk long after the initial intrusion. Stolen account data, contact information, or business records may be reused for phishing, credential attacks, identity fraud, or targeted social engineering. The source-backed facts above describe the incident; the downstream risk depends on what information was actually exposed.

What you should do

If you are notified that your information or account was affected, follow the organization’s incident instructions first. Change reused passwords, enable multifactor authentication, watch for targeted phishing, review security alerts and account sessions, and monitor financial or identity activity when sensitive personal information may have been involved.