Close Menu
    What's Hot
    Technology & Innovation

    Queensland Government and CSIRO launch free program to help SMEs advance AI and digital tech ideas

    By Art RyanAugust 26, 20260

    The free eight-week online program, delivered by Australia’s national science agency, CSIRO, helps businesses turn…

    Faria Education Group Acquires Edu Intelligence to Expand AI Analytics for Schools

    August 26, 2026

    Momentum AI Austin 2026 Puts Enterprise AI ROI Ahead of the Hype

    August 26, 2026

    Fake OpenAI Codex Ads Are Pushing Mac Malware Through Google Search

    August 26, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Breaking AI News
    Wednesday, August 26
    • Home
    • Events
    • Videos
      • Machine Can Think Summit 2026
      • Step Dubai Conference 2026
    • Technology & Innovation

      Queensland Government and CSIRO launch free program to help SMEs advance AI and digital tech ideas

      August 26, 2026

      Faria Education Group Acquires Edu Intelligence to Expand AI Analytics for Schools

      August 26, 2026

      Momentum AI Austin 2026 Puts Enterprise AI ROI Ahead of the Hype

      August 26, 2026

      Fake OpenAI Codex Ads Are Pushing Mac Malware Through Google Search

      August 26, 2026

      Sharjah Chamber launches executive training programme on AI and digital transformation at Oxford and Cambridge

      August 26, 2026
    • Business & Marketing

      Faria Education Group Acquires Edu Intelligence to Expand AI Analytics for Schools

      August 26, 2026

      e& UAE Bundles Microsoft Copilot Into Business Fibre Plans for SMEs

      August 26, 2026

      Mistral and HUMAIN Strike Major Saudi AI Deal Worth Hundreds of Millions of Euros

      August 26, 2026

      Culture Amp Brings Workplace Culture Intelligence Into ChatGPT and Claude With MCP

      August 25, 2026

      Syira AI Opens Doha Office as Qatar’s AI Market Adds Another Full-Stack Player

      August 24, 2026
    • Industry Applications

      Faria Education Group Acquires Edu Intelligence to Expand AI Analytics for Schools

      August 26, 2026

      e& UAE Bundles Microsoft Copilot Into Business Fibre Plans for SMEs

      August 26, 2026

      UK and Ukraine Sign Strategic AI Deal to Develop Battlefield Technology

      August 25, 2026

      Elastic Completes Deductive AI Acquisition to Push AI Deeper Into Production Incident Investigations

      August 25, 2026

      Culture Amp Brings Workplace Culture Intelligence Into ChatGPT and Claude With MCP

      August 25, 2026
    • Trends & Insights

      Gemini 4 Leaks Hint at Google’s Next Big AI Push in Coding and Agentic Workflows

      August 20, 2026

      AI Companies Are Looking to the Ocean for Their Next Data Centers

      August 18, 2026

      Alibaba’s Qwen Surges Past Google and Meta With 3 Billion AI Model Downloads

      August 17, 2026

      UK’s AI Boom Is Starting to Show Up in the Economy

      August 17, 2026

      Oracle Says $165 Billion Project Jupiter AI Data Center Is Still on Schedule

      August 15, 2026
    • AI in Travel

      AI Search Is Changing How Travelers Find Hotels — and Visibility May Become the New Booking Battleground

      August 25, 2026

      LuggageToShip Expands AI-Powered Travel Platform for Smarter Global Luggage Shipping

      August 21, 2026

      Agoda Launches AI Room Grid Bot to Make Hotel Room Selection Less Frustrating

      August 21, 2026

      Radisson’s AI Push Is Already Changing How Hotels Sell Rooms, Hire Staff and Prepare for AI Agents

      August 21, 2026

      Tourism Fiji Wins PATA Gold Award for AI-Powered Travel Ecosystem

      August 20, 2026
    Breaking AI News
    Home » Fake OpenAI Codex Ads Are Pushing Mac Malware Through Google Search
    Technology & Innovation

    Fake OpenAI Codex Ads Are Pushing Mac Malware Through Google Search

    Art RyanBy Art RyanAugust 26, 2026No Comments6 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    fake OpenAI Codex ads
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Searching Google for an AI coding tool should be routine. Recently, however, fake OpenAI Codex ads have resulted in a malware trap for some Mac users. For some Mac users, it became a malware trap.

    Cybercriminals are buying sponsored search ads that pretend to offer OpenAI Codex downloads. The ads lead developers to convincing fake pages hosted through Google Sites. Those pages use OpenAI branding and look believable at first glance.

    There is no real Codex installer waiting there.

    Instead, users are told to open Terminal and paste a command. That command quietly starts a multi-stage malware infection. Researchers at Cato Networks say the campaign shows strong similarities to Atomic macOS Stealer, or AMOS.

    Sponsored Google Results Are Being Used as the First Trap

    The attack begins with something developers do every day: search Google. Cato Networks found sponsored results targeting queries such as “Codex macOS download.” Those advertisements could appear above legitimate results. Clicking them sent users to Google Sites pages made to look official. The familiar Google domain adds another layer of trust. That makes the fake page easier to overlook.

    The Fake Codex Page Does Not Actually Download Codex

    The landing page shows download options for macOS and Linux. Cato only observed active malware delivery to Mac users. Rather than offering a normal installer, the page tells visitors to open Terminal. It then asks them to copy and run a supplied command. The instruction is presented as a normal installation step. That is where the attack moves from impersonation into execution.

    Attackers Are Using the ClickFix Technique

    The campaign relies on a social-engineering method known as ClickFix. It works differently from a traditional malicious attachment. The attacker convinces the victim to run the dangerous command themselves. In this case, the command starts with text that resembles a legitimate Codex installation. Hidden behind it is code that retrieves another script. That script is then passed into the Mac’s shell.

    Huntress Says the Attack Exploits Developer Muscle Memory

    Dray Agha, senior manager of security operations at Huntress, said the campaign shows how macOS attack methods are becoming more focused on social engineering. Instead of relying on a simple rogue download, attackers are taking advantage of habits developers already have.

    Agha said ClickFix-style attacks work because users are persuaded to run commands themselves. That helps attackers move around some traditional security controls. Developers are especially attractive targets because command-line installers are part of normal daily work.

    He also warned that search ads and Google Sites make the initial lure more convincing. Trusted platforms can hide malicious infrastructure and make a fake page look legitimate. According to Agha, organizations should tighten software provisioning rules. Endpoint monitoring should also treat unverified Terminal scripts with caution, even when the source page looks official.

    Agha said:

    “Because developers rely heavily on command-line installers daily, attackers are betting on muscle memory over caution.”

    His comments reinforce the central problem in this campaign. The attackers are not only exploiting software. They are exploiting familiar behavior.

    The Malware Arrives Through Several Stages

    Once the victim runs the Terminal command, the infection does not arrive all at once. Cato documented a three-stage delivery chain. The first script contains an encoded second stage. That stage reports execution and downloads the final payload. The malware is placed in a temporary directory. It is then made executable and launched. This layered approach makes the campaign harder to inspect quickly.

    The Malware Tries to Reduce macOS Security Warnings

    The attack also takes steps to weaken some of the warnings Mac users might normally see. The second-stage script clears extended file attributes. Those attributes can contain macOS quarantine information. Removing them can reduce the warning context presented to the user. The payload is then launched after its permissions are changed. It is a small technical step, but an important one for the attacker.

    Both Intel Macs and Apple Silicon Machines Can Be Targeted

    Cato found that the final payload uses a universal Mach-O format. That means it can execute on older Intel-based Macs and newer Apple Silicon systems. The attack is not limited to one Mac generation. Researchers observed components designed for both major architectures. That wider compatibility increases the number of developers the campaign can target.

    Researchers See Strong Links to Atomic macOS Stealer

    Cato stopped short of declaring the malware definitively to be AMOS. Still, the overlap is substantial. Researchers found similarities in how commands are decoded and how scripts are staged. They also found familiar payload locations and execution methods. The campaign uses techniques seen in earlier AMOS delivery chains. Cato described the activity as strongly consistent with that framework.

    The Fake Site Changes What Some Visitors See

    The criminals are also trying to make analysis more difficult. The visible Google Sites page is only part of the setup. Attacker-controlled content is loaded through an iframe. The infrastructure can examine details about the visitor. Someone using the wrong device may receive harmless content instead. Automated scanners can therefore miss the actual malware page.

    OpenAI Codex Is Not the Only AI Tool Being Impersonated

    The campaign extends beyond OpenAI branding. Cato also found a ClickFix landing page pretending to offer Anthropic’s Claude Code. Researchers said it reused infrastructure seen in the Codex operation. That suggests attackers are rotating recognizable AI developer brands. Popularity works in their favor. The more people search for a new AI coding tool, the larger the pool of potential victims becomes.

    AI Developer Tools Have Become Valuable Phishing Bait

    The lure makes sense from an attacker’s perspective. Developers are comfortable installing packages and running shell commands. AI coding products are also changing quickly. Users often search for setup instructions instead of relying on software they already know.

    That creates an opening for malicious ads and lookalike download pages. The fake page does not need a sophisticated exploit. It needs trust. A sponsored Google result looks familiar. Google Sites looks familiar. Codex looks familiar. Even the Terminal command can appear legitimate at first.

    Developers Should Verify AI Tool Downloads Before Running Commands

    The simplest defense is also easy to ignore. Developers should verify the official source before installing AI tools. Sponsored search results deserve extra scrutiny. A page asking users to paste an unfamiliar command into Terminal should also be treated cautiously.

    Organizations have another role to play. Software provisioning policies can reduce the number of unverified tools installed by employees. Endpoint monitoring can also flag suspicious shell activity. Huntress recommends treating copy-pasted Terminal commands with extreme suspicion when their origin cannot be verified.

    This campaign is another reminder that AI security is not only about model attacks or prompt injection. The surrounding ecosystem is now a target too. Attackers are borrowing trusted AI brands because developers already want the software. Sometimes the malware does not need to break in. It only needs to look like the tool someone was already searching for.

    Sources

    • The Register — Crooks push Mac malware through fake OpenAI Codex ads
      https://www.theregister.com/security/2026/08/25/crooks-push-mac-malware-through-fake-openai-codex-ads/5291899
    • Cato Networks — When Trust Becomes the Payload in a Fake Codex ClickFix Campaign
      https://www.catonetworks.com/blog/cato-ctrl-when-trust-becomes-payload-in-fake-codex-clickfix-campaign/
    • Huntress — ClickFix-style threat analysis
      https://www.huntress.com/
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Art Ryan

    Related Posts

    Queensland Government and CSIRO launch free program to help SMEs advance AI and digital tech ideas

    August 26, 2026

    Faria Education Group Acquires Edu Intelligence to Expand AI Analytics for Schools

    August 26, 2026

    Momentum AI Austin 2026 Puts Enterprise AI ROI Ahead of the Hype

    August 26, 2026

    Comments are closed.

    Latest News

    Queensland Government and CSIRO launch free program to help SMEs advance AI and digital tech ideas

    August 26, 2026

    Faria Education Group Acquires Edu Intelligence to Expand AI Analytics for Schools

    August 26, 2026

    Momentum AI Austin 2026 Puts Enterprise AI ROI Ahead of the Hype

    August 26, 2026

    Fake OpenAI Codex Ads Are Pushing Mac Malware Through Google Search

    August 26, 2026
    Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram LinkedIn YouTube Spotify Reddit Snapchat Threads

    AI University

    • Global Universities
    • Universities in Africa
    • Universities in Asia
    • Universities in Europe
    • Universities in Latin America
    • Universities in Middle East
    • Universities in North America
    • Universities in Oceania

    AI Tools & Apps Directory

    • AI Productivity Tools
    • AI Coding Tools
    • AI Voice Tools
    • AI Video Tools
    • AI Image Generators
    • AI Writing Tools

    Info

    • Home
    • About Us
    • AI Organizations & Associations
    • Contact Us
    • Cookie Policy
    • Copyright Policy
    • Disclaimer
    • Editorial Policy
    • Terms and Conditions

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2026 Breaking AI News.
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Sign Up

    Want to stay ahead In Artificial Intelligence?

     Sign up now and get exclusive breaking AI news and special updates—FREE!