The images in this article were generated with artificial intelligence. How we publish
Microsoft Threat Intelligence has documented a significant evolution in a campaign aimed at macOS that now uses a server gate that classifies visitors before showing them a malicious page. Instead of exposing dangerous instructions and commands directly into the HTML, attackers serve different content according to a browser fingerprint: crawlers, sandboxes or traffic that does not fit a real Mac get benign or blank pages, while visitors who meet specific criteria receive a decoy that requests to run a command in Terminal.
The technique does not change the basic premise of the attack: the infection continues to depend on the user copying and sticking an osfuscated command in Terminal. This command usually uses curl to recover and run remote scripts - e.g. a / curl /in the staging infrastructure - and ends by deploying infostealers such as AMOS or other components that exfilter credentials, browser data, cryptomoneda keys and sensitive files. If you don't hit or run the command, there's no compromise..

The new is the level of sophistication of the gate: a compact JavaScript (just a couple of KB) collects signals such as Navigator.platform (waiting for MacIntel), screen dimensions, WebGL signals, time zone, presence within iframes, touch support and counters that detect the opening of the developer's console. CanPlayType ("video / mp4") is even reused as a tripwire to detect browsers that fake codecs. The server receives that print and decides which version of the page to deliver; therefore two visits to the same domain can produce completely different content.
From a defensive perspective this complicates detection based on static crawling or sandbox services: dangerous content only appears for "qualified" visitors. Therefore Microsoft recommends to search and block the staging gate and infrastructure (e.g. path / curl /) rather than pursue front domains to use and pull. The detected operational pattern includes hundreds of front domains that combine terms such as "file" with dictionary words and repeated artifacts in shared infrastructure.
For response and incident teams the practical recommendation is to correlate web activity with actions in Terminal: a navigation that coincides in time with a curl pied to zsh, Base64 decoding, osascript calls, compressed file creation and outgoing POST connections is a strong commitment indicator. At network and gateway level, block or inspect applications to known staging path, apply disposable domain filtering and use browser isolation reduces exposure. Make Hunt by self-calling forms of prints, hidden fields of fingerprinting and the presence of the model marker: "php" can reveal the gate even when the front-end seems clean.
At the end-user level, the most effective defense remains the simplest: never paste or run commands in Terminal that arrive from a website, CAPTCHA, chat or mail. Apple, in its recent security updates and mitigation, introduced terminal-glued confirmations and XProtect capabilities to track and block malicious commands in macOS; keep the system up-to-date and respect confirmation windows reduces risk. For more context on technical publications and security notices, see reputable resources such as Microsoft's security blog Microsoft Security Blog and Apple security update documentation Apple - About Security Updates.

The operational implications go beyond a specific malware: the use of server- side digital footprint gates supports more targeted and resilient campaigns against automated analysis. This forces to combine controls in multiple layers: phishing prevention, endpoint policies that limit the execution of downloads from browsers, outgoing traffic inspection and endpoints detections that identify typical outflow and remote execution sequences.
Finally, for equipment that manage macOS in corporate environments, it is recommended to implement records that link web events with system activity, create rules in IMS that detect curl patterns - 124; zsh and unusual child processes, and prepare playbooks that quickly block identified staging infrastructure. The campaign illustrates an already observed trend where attackers leave the sending of disk images and prefer remote scripts that are released from Terminal; this requires an adaptation in user detection and training to refuse the critical gesture of hitting suspicious commands.
To expand understanding of tactics and techniques related to the theft of credentials and exfiltration, the MITRE ATT & CK knowledge repository can also be consulted at MITRE ATT & CK which helps map indicators and design defensive coverage aimed at this type of threat.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...