Some Mac users think they're installing OpenAI Codex, but it's actually a malware that can steal passwords in seconds
Crooks used Google Sites and stolen Google Ads accounts to push fake OpenAI Codex pages macOS users tricked into pasting Terminal commands, leading to AMOS infostealer infection Campaign abuses Google’s trust signals; Windows download button was a decoy, only Mac payload worked Cybercriminals were seen abusing Google Sites, the Google ad network, and OpenAI’s good name, in a campaign that targets macOS users with infostealers.
According to security researchers CATO CTRL, the crooks used Google Sites to create a fake version of the OpenAI Codex download site.
To avoid being flagged by Google’s security systems and ultimately removed, the site itself contains no malicious code or download links, whatsoever.
Instead, it hosts an iFrame that displays content hosted elsewhere.
Then, they advertised that site on the Google Ads network.
Google is usually good at spotting and preventing malicious ads from running on its network, but sometimes threat actors steal legitimate accounts with good standing and use them to bypass automated scans and get the ads listed, while also spending other people’s money on the ad campaign.
Not ClickFix The ads were displayed to users searching for “codex macos download”, at the very top of the page.
Using both Google Sites and Google Ads is a deliberate attempt to appear legitimate and trustworthy since after all, many people trust whatever Google displays as the top result without double-checking or scrutinizing the result.
Those that do click will see a website that, by all accounts, looks like OpenAI’s download site for Codex, the company’s AI coding agent .
The site has download buttons for both Windows and Mac, but only the latter works.
The download and installation process was designed to look “advanced” - instead of getting an executable, the victims are told to paste a command in Terminal.
Cato’s researchers call this a ClickFix attack, but ClickFix usually displays a fake problem, before offering an equally fake solution.
This looks more like another way to appear legitimate because after all, several AI agents are specifically designed to be installed and run from the macOS Terminal, including OpenAI’s Codex CLI.
The end goal of the campaign is to deploy AMOS, a known macOS infostealer capable of grabbing browser data, login credentials, cryptocurrency wallet information, and more.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.