9to5Mac Review: ClickFix Becomes Default Delivery Method for New Mac Stealers
9to5Mac review: ClickFix is now the default delivery route for almost every new Mac stealer.
According to 9to5Mac, ClickFix was previously described as the new kid on the block and the technique to watch. By the September review, it had become the default delivery method for almost every new Mac stealer, and threat actors were getting much better at using it, the publication said.
The review also reported that attackers have recently implemented persistence, backdoors, and infrastructure that hides inside Apple's own services. 9to5Mac presented those developments as part of the current Mac threat landscape for security practitioners and Mac owners concerned about malware.
The column said the author had expected to write about something new in the latest review but could not. That did not mean nothing was happening, according to the review, which said the opposite was true.
The Security Bite column is presented by Mosyle, an Apple Unified Platform provider. Mosyle says its platform combines Apple-specific security tools for hardening and compliance, next-generation EDR, AI-powered Zero Trust, and privilege management with Apple MDM, and is used by more than 45,000 organizations. This sponsorship disclosure appeared with the review.
Editor's Summary
9to5Mac's September Security Bite review says ClickFix has become the default delivery method for almost every new Mac stealer since the publication's Q1 2026 review. The review also cites recent attacker use of persistence, backdoors, and infrastructure hidden inside Apple's own services. It reports no new headline technique but describes continued evolution in Mac stealer operations.