Skip to content
Crooks Push Mac Malware Through Fake OpenAI Codex Ads

Crooks Push Mac Malware Through Fake OpenAI Codex Ads

Ground.News August 25, 2026

Crooks used Google Sites and stolen Google Ads accounts to push fake OpenAI Codex pagesmacOS users tricked into pasting Terminal commands, leading to AMOS infostealer infectionCampaign abuses Google’s trust signals; Windows download button was a decoy, only Mac payload workedCybercriminals were seen abusing Google Sites, the Google ad network, and OpenAI’s good name, in a campaign that targets macOS users with infostealers.According to security …

Cybercrims are using fake OpenAI Codex download pages to trick Mac developers into running malware disguised as installation commands. Researchers at Cato Networks uncovered the campaign after spotting Google results targeting people looking to download Codex for macOS. The ads direct would-be users to a convincing-looking download page hosted on Google Sites, complete with the familiar OpenAI branding. There is, however, no Cod…

Fake Codex pages used Google Sites, and ClickFix to target Mac users This article has been indexed from Read the original article: Fake Codex Download Uses Google Sites to Deliver macOS Malware

Cato Networks Ltd.’s Cato CTRL threat research team today detailed a macOS attack campaign built around a fake OpenAI Codex installer. The lure ends with the victim opening Terminal and pasting a command that runs the malware, the social engineering pattern known as ClickFix. It begins with a Google result for queries such […]

To view factuality data please Upgrade to Premium

To view ownership data please Upgrade to Vantage

Extracted Entities