Crooks Push Mac Malware Through Fake OpenAI Codex Ads
Researchers at Cato Networks said the campaign uses sponsored Google ads and a ClickFix-style command to deliver multi-stage malware.
5 Articles
5 Articles
Some Mac users think they're installing OpenAI Codex, but it's actually a malware that can steal passwords in seconds
Crooks used Google Sites and stolen Google Ads accounts to push fake OpenAI Codex pagesmacOS users tricked into pasting Terminal commands, leading to AMOS infostealer infectionCampaign abuses Google’s trust signals; Windows download button was a decoy, only Mac payload workedCybercriminals were seen abusing Google Sites, the Google ad network, and OpenAI’s good name, in a campaign that targets macOS users with infostealers.According to security …
Crooks push Mac malware through fake OpenAI Codex ads
Cybercrims are using fake OpenAI Codex download pages to trick Mac developers into running malware disguised as installation commands. Researchers at Cato Networks uncovered the campaign after spotting sponsored Google search results targeting people looking to download Codex for macOS. The ads direct would-be users to a convincing-looking download page hosted on Google Sites, complete with the familiar OpenAI branding. There is, however, no Cod…
"You have to deal with the legal consequences for every crime that was committed using your identity. Do you understand?" read more (08/24/2026
Fake Codex Download Uses Google Sites to Deliver macOS Malware
Fake Codex pages used Google Sites, sponsored search and ClickFix to target Mac users This article has been indexed from www.infosecurity-magazine.com Read the original article: Fake Codex Download Uses Google Sites to Deliver macOS Malware The post Fake Codex Download Uses Google Sites to Deliver macOS Malware appeared first on IT Security News.
Fake Codex installer tricks Mac users into pasting malware, Cato finds
Cato Networks Ltd.’s Cato CTRL threat research team today detailed a macOS attack campaign built around a fake OpenAI Codex installer. The lure ends with the victim opening Terminal and pasting a command that runs the malware, the social engineering pattern known as ClickFix. It begins with a sponsored Google search result for queries such […] The post Fake Codex installer tricks Mac users into pasting malware, Cato finds appeared first on Silic…
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium











