← Back to blog

Mac Malware Campaign Uses Browser Fingerprinting to Evade Detection

Over 250 domains linked to the ClickFix macOS malware now use browser fingerprinting to hide payloads from security tools. The campaign selectively serves malicious downloads to Mac users while blocking crawlers and sandboxes.

TL;DR

  • More than 250 domains tied to macOS ClickFix malware now use browser fingerprinting
  • Malicious pages are hidden from crawlers, sandboxes, and non-targeted users
  • Only specific Mac users are shown fake software download prompts
  • Microsoft Threat Intelligence has been tracking this evolving infrastructure
  • Campaign demonstrates increasing sophistication in evading detection

A sophisticated macOS malware operation has evolved its tactics to evade automated detection systems. The ClickFix campaign now spans over 250 domains that employ browser fingerprinting techniques to determine which visitors receive malicious content.

This server-side filtering allows attackers to hide their payload distribution pages from security scanners, crawlers, and sandbox environments. Only users meeting specific browser and system criteria—particularly macOS users—are presented with fake software download prompts designed to install malware.

Technical Evasion Tactics

  • Domains perform browser fingerprinting to identify and block security analysis tools
  • Server-side logic determines whether to serve legitimate content or malware lures
  • Crawlers and automated systems are presented with clean pages to avoid detection
  • Real targets see fake software updates or download prompts specifically crafted for macOS

Operational Impact

  • Campaign demonstrates advanced understanding of security tool behaviors
  • Infrastructure can scale across hundreds of domains while maintaining evasion capabilities
  • Selective targeting reduces exposure while maximizing infection success rates
  • Represents growing trend of malware-as-a-service operations adopting enterprise-grade evasion

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Mac Malware Campaign Uses Browser Fingerprinting to Evade Detection — Agent Breach Blog | Agent Breach