HackerFeeds

CyberSecurity News

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

The Hacker News
· August 5, 2026

AI summary

A large-scale ClickFix operation involving over 250 domains has been found to use browser fingerprinting to determine which visitors to show malware lures to. This tactic allows the operation to hide the malicious content from crawlers and sandboxes, while targeting specific Mac users with fake software downloads. Microsoft Threat Intelligence has been tracking the infrastructure behind this operation for weeks, observing the use of server-side gates to control who sees the malware. The fingerprinting technique enables the operation to selectively present the malicious page to chosen visitors. The goal of this approach is to evade detection and present a fake download to targeted Mac users. Microsoft has been monitoring the development of this tactic.

Read the full article at The Hacker Newsthehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.