Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
Threat actors are abusing fake OpenAI Codex download pages to trick macOS users into running malware through Terminal.