AI News Feed
Market watch
Cybersecurity

Fake OpenAI Codex Pages on Google Ads Deliver AMOS Password-Stealing Malware to Macs

Cybercriminals are using fake OpenAI Codex sites on Google Ads to spread AMOS infostealer to Mac users, researchers at CATO CTRL found.

The researchers said the attackers built the fraudulent page on Google Sites, which contains no malicious code or links itself. Instead, it uses an iFrame to display content hosted elsewhere, a measure that helps it avoid being flagged and removed by Google's security systems.

The page was then promoted through Google Ads. The threat actors stole legitimate ad accounts in good standing to bypass automated scans and run the ads, while spending the account owners' money, CATO CTRL said. The ads were shown at the top of search results for queries like "codex macos download."

Visitors who clicked saw what looked like OpenAI's official Codex download page, with downloadable buttons for Windows and Mac. Only the Mac version worked. The installation process appeared intentionally "advanced": rather than providing an installer file, the page told victims to paste a command into the macOS Terminal.

CATO CTRL described this as a ClickFix-style attack, but noted the approach may have been chosen to look legitimate because AI agents such as OpenAI's Codex CLI are normally installed and run from Terminal.

The campaign's end goal is to deploy AMOS, a known macOS info-stealer that can collect browser data, login credentials, cryptocurrency wallet details, and other sensitive information.