AI News Feed
Market watch
Cybersecurity

Security experts targeted by fake crypto conference in ClickFix campaign, researchers warn

A ClickFix campaign on X lures security professionals with fake conference invites to install AMOS infostealer, according to Huntress researchers.

The campaign focuses on individuals who have attended or shared content from major cybersecurity conferences such as Black Hat and DEF CON. The attack starts on X, where a threat actor uses a fake account to interact with people engaging with conference content. After establishing rapport, the attacker moves to direct messages, claims to be organizing their own conference, and shares a Google Docs file described as containing "more info."

The document includes a vertical sidebar presented as a security feature to keep the file's contents encrypted. Victims are given a decryption code to enter, but it returns an error and prompts them to open Terminal and copy-paste a piece of code. This ClickFix method leads to the download and execution of AMOS, a known macOS infostealer capable of grabbing browser information, cookies, keychain data, cryptocurrency wallet information, Telegram files, and more. Huntress noted that the Windows variant they analyzed did not work, but the likely goal remains the same.

The attack does not end there, according to Huntress. If a victim does not install the infostealer, the threat actor follows up with a different document disguised as a Dropbox file that requires the desktop app. The download button again directs to the infostealer.

Huntress published a list of indicators of compromise and advised anyone who interacted with the lure to isolate the system from the network and collect forensic evidence. "Assume that credentials on the system have been compromised," the researchers said. "Revoke active sessions, reset passwords, and rotate API keys or any other secrets that may reside on the system. Review cryptocurrency wallets as well, if present."