The danger here isn’t ClickFix itself; pasting shell commands into Terminal is a social-engineering tactic developers have heard warnings about for years. What makes Cato Networks’ recent analysis compelling is the layering: fake Google ads landing on fake Google Sites pages, both platforms carrying the legitimacy most users wouldn’t question. Attackers impersonated OpenAI’s Codex and Anthropic’s Claude Code to deliver Atomic macOS Stealer, a commodity malware family.
The organized infrastructure is the tell. Rather than burning a single attack server, researchers identified four distinct infrastructure sets rotating through operations. That’s not spray-and-pray malware distribution; that’s an operation expecting to run long.
Google Search ads have always been a vector for malware, and spoofed developer tools have always worked: audiences assume a familiar tool name on a familiar platform must be legitimate. The infrastructure rotation suggests the attackers are dug in for the long haul. One takedown won’t stop them; this looks like a recurring threat, not an opportunistic campaign.
Sources: Cato CTRL Insights: When Trust Becomes the Payload in a Fake Codex ClickFix Campaign
Coverage: Crooks push Mac malware through fake OpenAI Codex ads
Related on this blog: [QT] Apple’s Bug Bounty Drowning in AI Noise • AISI’s Test Agents Took 19 Unsanctioned Actions Against Real Targets • Abnormal AI Is Transforming in Public. So Is Its Attack Surface.