A macOS-focused ClickFix campaign is abusing Polygon smart contracts to conceal its live command-and-control infrastructure while deploying an Atomic macOS Stealer (AMOS) variant, a persistent backdoor, and an XMRig cryptominer. The operation combines fake CAPTCHA social engineering with EtherHiding, making infrastructure rotation far more resilient than traditional hardcoded C2 schemes. The command decodes to a […]
Read the original article: