Devious new ClickFix malware variant targets macOS, Android, and iOS using browser-based redirections


- Security researchers found ClickFix attacks evolving to target other operating systems
- On Android and iOS, the attack is particularly worrisome, as it transforms into a drive-by attack
- The malware is already being flagged by antivirus programs
ClickFix, an infamous hacking technique that tricks people into running malware thinking they’re fixing a problem on their computer, has evolved, experts have warned.
New research from c/side has revealed what used to be a Windows-only attack method is now capable of targeting macOS, iOS and Android devices, as well.
In a blog post analyzing the evolution, the researchers said the new attack starts with a compromised website. The threat actors would inject JavaScript code which redirected users to a new browser tab when they clicked on certain elements on the page. The new tab then displays a page that looks like a legitimate URL shortener, with a message to copy and paste a link into the browser – and doing so triggers yet another redirect, this time to a download page.
Fetching the malicious payload
Here is where the technique diverges, depending on the operating system of the victim.
On macOS, the attack leads to a terminal command that fetches and executes a malicious shell script, already flagged by multiple antivirus programs.
On Android and iOS, things are even worse, since the attack no longer requires any user interaction.
“When we tested this on Android and iOS, we expected a ClickFix variant. But instead, we encountered a drive-by attack,” the researchers explained.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
“A drive-by attack is a type of cyberattack where malicious code is executed or downloaded onto a device simply by visiting a compromised or malicious webpage. No clicks, installs, or interaction required.”
In this case, the site downloads a .TAR archive file, holding malware. This one, too, was flagged by at least five antivirus programs already.
“This is a fascinating and evolving attack that demonstrates how attackers are expanding their reach,” c/side explained. “What started as a Windows-specific ClickFix campaign is now targeting macOS, Android, and iOS, significantly expanding the scale of the operation.”
You might also like
Security researchers found ClickFix attacks evolving to target other operating systems On Android and iOS, the attack is particularly worrisome, as it transforms into a drive-by attack The malware is already being flagged by antivirus programs ClickFix, an infamous hacking technique that tricks people into running malware thinking they’re fixing…
Recent Posts
- Devious new ClickFix malware variant targets macOS, Android, and iOS using browser-based redirections
- Nebraska to adopt law aimed at curbing kids’ time online
- How we test VPNs
- It’s official, Android users: Instagram is draining your battery, but there’s now a fix
- QA workers at ZeniMax reach tentative contract agreement
Archives
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010