// 9TO5MAC — MOBILE & WEB
Security Bite: Mac threat landscape review (September)
9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.
Every few months, I sit down to look back at the Mac threat landscape, and every time I expect to write about something new. This time I can’t. But that doesn’t mean nothing is happening. In fact, the opposite.
Since I published the Security Bite Q1 2026 review, we’ve seen ClickFix go from the new kid on the block and the technique to watch to now the default delivery method for almost every new Mac stealer. Threat actors are getting much better at using it too (I suppose the kids would call this “locked in”). Recently we’ve seen attackers implement persistence, backdoors, and even infrastructure that hides inside Apple’s own services.
Here’s what you should know as a security practitioner or a malware-fearing Mac owner…
To no one’s surprise, Apple’s 26.4 Terminal prompts didn’t slow this attack vector down.
Nearly every new Mac malware family from the past few months arrived the same way: a fake CAPTCHA or “fix” page that gets the victim to paste a command into Terminal themselves. ClickLock, discovered by Group-IB. A new Go-based stealer Huntress spotted in August. The latest MacSync variant, which Kaspersky found spreading through pages posing as Homebrew and a disk space cleanup tool. More on each soon.
What makes ClickFix so successful is that it doesn’t need to go up against Gatekeeper, notarization, XProtect, or any of the Mac’s incredibly capable antivirus tools. This is really because the user is coerced into infecting themselves by running the script. Apple’s warning prompts were a good first step, but attackers are scrappy and will always find ways around. Like Script Editor.
So, ClickFix is the delivery technique. Now let’s talk about the payload.
In its old school form, a Mac infostealer was very much a smash and grab. It would run once, dump your passwords and crypto wallets to something like a Telegram bot, and then vanish. That’s certainly not the case anymore. Just this year, we’ve seen examples like ClickLock that social engineer users into giving up their system password and leave a backdoor behind for round two.
MacSync, which came into the world as an AMOS lookalike, picked up a backdoor module too. Moonlock Lab put it best in its mid-year report, saying the 2026 model isn’t a stealer, it’s a persistent implant that happens to start with stealing.