Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIOver 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
Microsoft Threat Intelligence has identified a sophisticated macOS-targeted ClickFix campaign operating across over 250 domains that employs browser fingerprinting to selectively display malware lures. The server-side filtering mechanism allows attackers to evade detection by security crawlers and sandbox environments while specifically targeting Mac users with fraudulent software downloads.
AIDPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
North Korean threat actors are conducting a sophisticated macOS malvertising campaign that redirects users to fake software update pages to deliver crypto-stealing malware. This represents a new evolution of the ongoing Contagious Interview campaign, using deceptive full-screen update sequences to trick macOS users into installing malicious software.
AIFlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads
Cybersecurity researchers have identified a macOS malvertising campaign called Operation FlutterBridge that distributes the FlutterShell backdoor through malicious Google and YouTube advertisements. Palo Alto Networks Unit 42 reports this represents an evolution of the JSCoreRunner (FileRipple) attack cluster previously documented in August 2025, indicating an ongoing and adapting threat campaign
