# A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)

Publisher-attributed story with a reviewed brief or permitted publisher paragraph. The original publisher is responsible for the linked reporting.

- Publisher: SANS Internet Storm Center
- Category: Cyber
- Original publication time: 2026-09-25T12:45:19Z
- First observed by NexusTechWire: 2026-10-01T18:42:00Z
- Original source: https://isc.sans.edu/diary/rss/33368
- NexusTechWire record: https://nexustechwire.com/news/news-693b298a0b947677b355

## The brief

SANS researcher Brad Duncan examined a macOS infection delivered through a fake verification prompt and found an information stealer with persistence and separate processor-specific payloads. His follow-up questions an earlier identification as AMOS because several behaviors differ. The diary documents the observed activity while leaving the malware-family attribution unresolved, rather than presenting the initial label as confirmed.

AI-assisted NexusTechWire summary, checked against the linked source on 2026-10-01T19:16:00Z. Not independent reporting.

Read the full original: [SANS Internet Storm Center](https://isc.sans.edu/diary/rss/33368)

This record does not reproduce the complete article or represent independent confirmation of every source claim.
