Google Sites Used in macOS Malware Campaign Targeting Users with OpenAI Impersonation
A recent campaign has been discovered using Google Sites to deliver macOS malware to unsuspecting users. The fake Codex download portal, which impersonated an OpenAI Codex download portal, offered both macOS and Linux download options but only delivered active payload for macOS.
The Google Sites pages embedded attacker-controlled content through an iframe, allowing the operators to use a trusted hosting domain while keeping the active ClickFix content on separate infrastructure. The campaign used sponsored search results and legitimate Google Sites pages to trick users into executing malware.
Cato Networks researchers found that the fake installer instructed victims to open Terminal and paste a command presented as a legitimate-looking Codex installation, which decoded an encoded URL and retrieved a shell script that continued the infection chain.