LIVE · cybersecurity feed
Live wire
malware

Fake Codex Download Uses Google Sites to Deliver macOS Malware

Fake Codex pages used Google Sites, sponsored search and ClickFix to target Mac users

zeroday.news ·

A new campaign is leveraging sponsored search results and legitimate Google Sites pages to distribute macOS malware, tricking users into executing malicious commands under the guise of installing OpenAI's Codex. The campaign was detailed in a technical write-up published on August 24 by researchers at Cato Networks.

The attack begins when users search for terms like "codex macos download" and are directed to sponsored results. These results lead to Google Sites pages that mimic an official OpenAI Codex download portal. While the fake portal offers download options for both macOS and Linux, active payload delivery has only been observed for macOS.

The Google Sites pages serve as a front, embedding attacker-controlled content through an iframe. This allows the attackers to use a trusted domain for the initial interaction while hosting the active malicious content on separate infrastructure. Cato Networks identified three distinct infrastructure sets involved in the campaign, with one iframe host being reused across two of them.

To evade detection, one set of infrastructure served the active malicious page from an unexpected URL path, while the more intuitive path returned a benign, fake product page. Additionally, the Google Sites lure displayed harmless content when accessed from a non-macOS device. This operating-system-aware gating could cause automated analysis tools or researchers to encounter a benign page instead of the active lure.

Victims who proceed are instructed to open Terminal and paste a command, presented as a legitimate Codex installation instruction. This command, however, decodes an encoded URL and retrieves a shell script, initiating a three-stage infection chain. The first stage involves a shell-script loader, which decodes and executes a second-stage script. This second script records that the victim has pasted the command before fetching the final Mach-O payload.

Before launching the final payload, the second stage places it in the `/tmp/helper` directory and strips its extended attributes. This action removes the download-related quarantine metadata that typically triggers macOS warnings for files downloaded from the internet.

Cato Networks researchers noted significant similarities between this campaign's delivery framework and previously documented Atomic macOS Stealer (AMOS) infection chains. These overlaps include the use of encoded shell loaders, telemetry requests, update-themed payload retrieval, and universal Mach-O payloads designed to run on both Intel and Apple Silicon Macs, staged in `/tmp/helper`. While the researchers described the overlap as strong and consistent with AMOS delivery activity, they cautioned that the delivery telemetry alone does not confirm the final payload is AMOS or how it behaves once executed.

The campaign aligns with a broader trend of AI-tool impersonation and "ClickFix" campaigns that exploit trusted platforms and common developer workflows. For effective defense, Cato Networks advises correlating indicators such as sponsored-search delivery, embedded web content, Terminal execution, and outbound network activity, rather than relying on any single indicator.

malwarepatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-69414

CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

Executive Summary ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender, allowing a low-privilege local attacker to escalate to SYSTEM. A public PoC was released on August 12, 2026, and Microsoft assigned the CVE on August 14, and no patch is available yet. Qualys VMDR provides detection […]

security

New TCG guidance gives buyers a way to test PQC-ready TPM claims

The Trusted Computing Group has published requirements that spell out what a Trusted Platform Module has to do before anyone calls it quantum-safe. A TPM is the chip that holds a machine’s keys and records measurements of its firmware, so the platform can later prove it has not been altered. Buyers can now ask a vendor for evidence against a written baseline. TCG’s requirements for Trusted Platfor

nation-state

Cybersecurity jobs available right now: August 25, 2026

Specialist Compliance Security AT&T | USA | On-site – View job details As a Specialist Compliance Security, you will serve as AT&T’s liaison for law enforcement, first responders, and emergency personnel nationwide. Respond 24×7 to emergency requests, process subpoenas, warrants, and court orders, and provide authorized subscriber, location, and call record information while acting as custodian of

nation-statecritical

US sanctions Iranian cyber actors as UK discloses power plant attack

The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.

cloud

SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules

The 6-3 decision dismisses one lawsuit brought by states, saying they have no standing to sue because the disputed sections “neither requires nor forbids anything of anyone outside the executive branch.” The post SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules appeared first on CyberScoop.

CVE-2026-73570

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.