By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Macs under threat from new malware campaign impersonating major ISP — how to stay safe
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Macs under threat from new malware campaign impersonating major ISP — how to stay safe
News

Macs under threat from new malware campaign impersonating major ISP — how to stay safe

News Room
Last updated: 2025/06/09 at 11:51 PM
News Room Published 9 June 2025
Share
SHARE

Even though people often think Macs are safe from malware, that definitely isn’t true. Case in point, a new Atomic Stealer campaign which is being used to infect the best MacBooks and other Apple computers with info-stealing malware has been spotted online.

As reported by The Hacker News, the campaign was discovered by the cybersecurity firm CloudSEK and it’s believed to be the work of Russian hackers due to comments in the malware’s source code.

What makes this campaign particularly interesting is the fact that in addition to typosquatting, it also uses social engineering to trick unsuspecting Mac users into falling for it. For those unfamiliar, typosquatting is a type of attack where cybercriminals register lookalike domains in order to lay traps for potential victims who mistype a popular site’s URL into their browser’s address bar. While they might think they’re on a popular company’s website, instead, they’re actually on a fake site designed to mimic the real one which is also used to spread dangerous malware.


You may like

Once infected with Atomic Stealer, the malware can steal personal and sensitive data from your Mac like passwords stored in your Apple Keychain, browser cookies, login credentials, credit card details and more.

Here’s everything you need to know about this new malware campaign along with some tips and tricks to prevent you from falling victim to it and other cyberattacks.

Not the Spectrum you were looking for

(Image credit: CloudSEK/Tom’s Guide)

According to CloudSek, the hackers behind this new campaign are impersonating the U.S. internet and cable provider Spectrum using a number of different fake sites. While Spectrum’s official website can be found at spectrum[.]com, in its blog post, the firm highlights one of these fake sites which uses the URL panel-spectrum[.]net.

Once on this fake site, potential victims are asked to complete a reCAPTCHA to verify that they aren’t bots. Since many sites use this or similar forms of verification, many people might not even think twice when asked to check a box to prove they’re human. However, on the fake site shared by CloudSek, once verification fails, potential victims are then asked to complete an alternative verification instead.

Get instant access to breaking news, the hottest reviews, great deals and helpful tips.

However, when someone clicks on the button that reads “Alternative Verification”, a command is copied to their clipboard without their knowledge. A set of instructions appears that asks them to open a command prompt, paste the code that was copied to their clipboard and to hit “Enter” to run it on Windows. If someone is using a Mac though, slightly different instructions are shown that lead to the same outcome, they’re computer being infected with info-stealing malware.

On Macs, a malicious shell script is used to steal system passwords and download a variant of the Atomic Stealer malware. As CloudSek security researcher Koushik Pal points out in the company’s report, the script “uses native macOS commands to harvest credentials, bypass security mechanisms, and execute malicious binaries.”

How to stay safe from Mac malware

A padlock resting next to the Apple logo on the lid of a gold-colored Apple laptop.

(Image credit: robert coolen/Shutterstock)

Given that hackers use all kinds of different tricks to lead potential victims to fake sites spreading malware, it’s always best to type a company’s website into your browser’s address bar manually. However, you should also double check that you spelled it correctly.

If you don’t know a company’s official site, you can use a search engine to find it. One thing though that you want to be careful about is that you’re not clicking the first link that you see. The reason being is that Google and on other search engines, the links at the top are often ads while finding a company’s actual website often requires that you scroll a bit further down the page. The problem with clicking on an ad or a sponsored search result is that cybercriminals often use malicious ads to take users to fake sites instead of to a company’s actual site as anyone (even hackers) can buy ad space online.

From here, it’s a matter of knowing how to identify a ClickFix attack. Many sites ask that you complete a reCAPTCHA or other form of verification before entering. However, if a site asks you to open a command window and paste something from your clipboard there before hitting “enter”, this is a major red flag. A legitimate company might ask you to select all of the images that are cars but they would never copy code to your clipboard without your knowledge and then ask you to paste and run it somewhere else.

Although your Mac does come with built-in security software in the form of Apple’s own XProtect, it’s still a good idea to consider investing in one of the best Mac antivirus software solutions. Unlike free antivirus software, these paid options are updated more frequently and are more likely to spot and help you avoid newer malware strains like Atomic Stealer.

Given that attacks using this ClickFix technique have proven both successful and profitable for hackers and other cybercriminals, they’re not going anywhere anytime soon. This is why it makes sense to educate yourself and your family members about these sorts of threats so that you can spot any red flags before your Mac or PC becomes infected with malware.

More from Tom’s Guide

Today’s Intego deals

Intego
Intego

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article The 2025 Guide to Food & Beverage Influencer Marketing
Next Article Retroid’s $69 second screen is ready for your favorite DS games
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

How Much Will the iPhone 17 Cost? Tariffs May Be Impossible to Avoid, but Could Prices Really Start at $1,400?
News
Weekly Newsletter 285407
News
Unlocking Insights: How LMS Advanced Analytics Enhance Learning Outcomes
Computing
Payroll data fintech Teal closes £1.4m pre-seed round – UKTN
News

You Might also Like

News

How Much Will the iPhone 17 Cost? Tariffs May Be Impossible to Avoid, but Could Prices Really Start at $1,400?

14 Min Read

Weekly Newsletter 285407

0 Min Read
News

Payroll data fintech Teal closes £1.4m pre-seed round – UKTN

3 Min Read

Getty Images and Stability AI face off in British copyright trial that will test AI industry

2 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?