Some Mac users think they're installing OpenAI Codex, but it's actually a malware that can steal passwords in seconds
Date:
Tue, 25 Aug 2026 12:35:00 +0000
Description:
An elaborate scheme was designed to deploy AMOS, a known macOS infostealer malware.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Crooks used Google Sites and stolen Google Ads accounts to push fake OpenAI Codex pages macOS users
tricked into pasting Terminal commands, leading to AMOS infostealer infection Campaign abuses Googles trust signals; Windows download button was a decoy, only Mac payload worked Cybercriminals were seen abusing Google Sites, the Google ad network, and OpenAIs good name, in a campaign that targets macOS users with infostealers.
According to security researchers CATO CTRL, the crooks used Google Sites to create a fake version of the OpenAI Codex download site. To avoid being flagged by Googles security systems and ultimately removed, the site itself contains no malicious code or download links, whatsoever. Instead, it hosts
an iFrame that displays content hosted elsewhere. Then, they advertised that site on the Google Ads network. Google is usually good at spotting and preventing malicious ads from running on its network, but sometimes threat actors steal legitimate accounts with good standing and use them to bypass automated scans and get the ads listed, while also spending other peoples money on the ad campaign. Latest Videos From TechRadar Watch full video here: Not ClickFix The ads were displayed to users searching for codex macos download, at the very top of the page. Using both Google Sites and Google Ads is a deliberate attempt to appear legitimate and trustworthy since after all, many people trust whatever Google displays as the top result without double-checking or scrutinizing the result.
Those that do click will see a website that, by all accounts, looks like OpenAIs download site for Codex, the companys AI coding agent . The site has download buttons for both Windows and Mac, but only the latter works. The download and installation process was designed to look advanced - instead of getting an executable, the victims are told to paste a command in Terminal. You may like Experts warn this fake Claude install guide can be used to empty crypto wallets Experts warn Claude feature hijacked by hackers to launch
major malware campaign Experts warn hackers are hiding malware inside
Google's own ad systems here's what we know
Catos researchers call this a ClickFix attack, but ClickFix usually displays
a fake problem, before offering an equally fake solution. This looks more
like another way to appear legitimate because after all, several AI agents
are specifically designed to be installed and run from the macOS Terminal, including OpenAIs Codex CLI.
The end goal of the campaign is to deploy AMOS, a known macOS infostealer capable of grabbing browser data, login credentials, cryptocurrency wallet information, and more. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners
or sponsors By submitting your information you agree to the Terms &
Conditions and Privacy Policy and are aged 16 or over.
Via SiliconANGLE The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/some-mac-users-think-theyre-installing- openai-codex-but-its-actually-a-malware-that-can-steal-passwords-in-seconds
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)