Connect with us

Technology

Shamos malware tricks Mac users with fake fixes

Published

on

Shamos malware tricks Mac users with fake fixes

NEWYou can now listen to Fox News articles!

A dangerous new malware campaign is targeting Mac users worldwide. Security researchers at CrowdStrike uncovered Shamos, a new variant of the Atomic macOS Stealer (AMOS), developed by a cybercriminal group called COOKIE SPIDER.

The attack relies on ClickFix tactics, where victims searching for Mac troubleshooting help are lured to fake websites or GitHub repositories. These spoofed sites trick users into copying and pasting a one-line command in Terminal, supposedly to fix an error. Instead, the command silently downloads Shamos, bypasses macOS Gatekeeper protections, and installs the malware.

Once inside, Shamos searches for sensitive data, Apple Notes, Keychain items, browser passwords, and even cryptocurrency wallets. The stolen information is zipped and sent directly to attackers, often alongside additional malware like botnet modules or fake Ledger wallet apps.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM/NEWSLETTER  

Advertisement

10 WAYS TO SECURE YOUR OLDER MAC FROM THREATS AND MALWARE

Malicious sponsored results can be seen on Google search. (CrowdStrike)

How Shamos malware spreads on macOS

Cybercriminals distribute these fake “fixes” through so-called “malvertising” campaigns and spoofed tech help sites with names like mac-safer[.]com or rescue-mac[.]com. These pages pose as trusted troubleshooting guides and appear in search results for common Mac issues, such as “how to flush resolver cache.”

The websites encourage victims to copy and paste commands that download malicious Bash scripts. These scripts grab the user’s password, remove file protections, and launch Shamos. With persistence tools installed, the malware can even restart alongside the system, keeping control long after the initial infection.

CAPTCHAGEDDON SIGNALS A DANGEROUS SHIFT

Advertisement

A fake help page provides victims with false instructions about how to fix problems with their Mac computer. (CrowdStrike)

Tips to stay safe from Shamos malware

You can avoid falling victim to Shamos and similar threats with these proactive steps:

1) Never run commands you don’t understand

Copy-pasting commands into Terminal may seem like an easy fix, but it’s also one of the easiest ways for attackers to bypass Apple’s built-in protections. If you see a command on a website, forum, or GitHub repository, don’t execute it unless you fully understand what it does. Instead, confirm with Apple’s official support site or the Apple Community forums, where experienced users and moderators can verify safe troubleshooting steps.

2) Avoid sponsored results

Hackers know that when your Mac has a problem, you’ll search for a quick solution. That’s why they buy sponsored ads like the one below to push fake troubleshooting websites higher in search results. Clicking the top link may feel natural, but it could be a trap. Stick with trusted sources like Apple Support, or scroll past the ads to find legitimate guides.

 

Advertisement

Fake instructions on how to fix printer issues on macOS. (CrowdStrike)

3) Be wary of GitHub projects

GitHub is an amazing resource for developers, but it’s also become a hotspot for malicious repositories that mimic legitimate software. Attackers often clone popular apps or tools, then hide malware inside. Before downloading anything, check the publisher’s name, stars, and activity history. If the account looks suspicious, inactive, or brand-new, avoid it.

4) Use strong antivirus protection

Mac malware is evolving fast, and Apple’s built-in security features can’t catch everything. A strong antivirus adds another layer of defense by scanning downloads, blocking malicious scripts, and detecting suspicious behavior in real time. Some security tools can even spot the one-line Terminal commands used by Shamos before they cause harm.

Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com/LockUpYourTech

5) Use a personal data removal service

Since Shamos is designed to steal personal information and send it to cybercriminals, reducing your online footprint can help limit the fallout. A personal data removal service scans data broker sites and removes your exposed information, making it harder for attackers to resell or exploit it after a breach. While this won’t stop malware from stealing what’s on your Mac, it adds another layer of protection by minimizing the data criminals can use against you.

Advertisement

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com/Delete

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com/FreeScan 

6) Keep macOS updated

Apple regularly patches vulnerabilities in macOS that malware tries to exploit. By keeping your system up to date, you close the doors that attackers rely on. Enable automatic updates, so your Mac receives the latest patches as soon as they’re available. Pairing this with good digital hygiene, like avoiding shady downloads, dramatically lowers your risk of infection.

Kurt’s key takeaways

Cybercriminals know that when your Mac breaks, you’ll look for quick answers. Shamos takes advantage of that urgency by disguising itself as help. Staying safe means slowing down before you copy, paste, or download anything. If something feels off, it probably is.

Should Apple be doing more to protect Mac users from evolving threats like Shamos? Let us know by writing to us at Cyberguy.com/Contact

Advertisement

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM/NEWSLETTER

Copyright 2025 CyberGuy.com. All rights reserved.

Advertisement

Technology

Canvas is down as ShinyHunters threatens to leak schools’ data

Published

on

Canvas is down as ShinyHunters threatens to leak schools’ data

The Instructure-owned learning management platform, Canvas, is down after recently confirming a massive data breach that impacted student names, email addresses, ID numbers, and messages. Students attempting to access the system on Thursday saw a message from the hacking group ShinyHunters, which claimed responsibility for the attack:

ShinyHunters has breached Instructure (again). Instead of contacting us to resolve it they ignored us and did some “security patches.” If any of the schools in the affected list are interested in preventing the release of their data, please consult with a cyber advisory firm and contact us privately at TOX to negotiate a settlement. You have till the end of the day by 12 May 2026 before everything is leaked.

The message included a link to a list of schools ShinyHunter claims to have breached through Canvas.

“Instructure has placed Canvas, Canvas Beta and Canvas Test in maintenance mode,” according to Infrastructure’s status page. “We anticipate being up soon, and will provide updates as soon as possible.”

Instructure said last week that it “deployed patches to enhance system security” following the breach. ShinyHunters — which has claimed responsibility for attacks on Ticketmaster, AT&T, Rockstar Games, ADT, and Vercel — said its data leak site contains 9,000 schools, including data belonging to 275 million students, teachers, and other staff, according to Bleeping Computer.

Update, May 7th: Added Infrastructure’s maintenance mode message.

Advertisement
Continue Reading

Technology

Humanoid robot named ‘Gabi’ ordained as Buddhist monk, pledges devotion to ‘holy Buddha’

Published

on

Humanoid robot named ‘Gabi’ ordained as Buddhist monk, pledges devotion to ‘holy Buddha’

NEWYou can now listen to Fox News articles!

A high-tech humanoid robot was officially “ordained” as a Buddhist monk during a ceremony at Seoul’s Jogyesa Temple on Wednesday.

The robot, a $13,500 Unitree G1 model standing just over four feet tall, was given the name “Gabi.” Dressed in traditional brown robes, plain shoes and gloves designed to mimic human hands, the machine stood before a panel of Buddhist monks to commit itself to the faith.

During the ceremony, hosted by the Jogye Order of Korean Buddhism, the robot was asked by a monk if it would devote itself to the “holy Buddha.”

“Yes, I will devote myself,” Gabi responded to the crowd’s cheers.

Advertisement

AI HUMANOID ROBOT LEARNS TO MIMIC HUMAN EMOTIONS AND BEHAVIOR

More than 200 humanoid robots perform during Agibot Night, a live televised gala in Shanghai ahead of Lunar New Year. (Tang Yanjun/China News Service)

The ceremony highlights a growing effort among religious institutions to engage younger, tech-driven audiences, raising broader questions about whether artificial intelligence can play a meaningful role in spiritual life or if such moves risk trivializing long-standing traditions.

While humans typically pledge to abstain from killing, stealing and intoxicating substances, Gabi’s vows were “reprogrammed” for the digital age. The robot pledged to respect and follow humans, refrain from damaging property or other robots, abstain from deceptive behavior and save energy by not overcharging.

The Jogye Order, South Korea’s largest Buddhist sect, framed the move as an effort to make ancient traditions more relevant to a younger, tech-obsessed generation.

Advertisement

HUMANOID ROBOT TURNS HEADS AT NYC SNEAKER STORE

A humanoid robot, front, and Buddhist monks put hands together for a photo after an ordination ceremony ahead of upcoming Buddha’s birthday on May 24 at Jogye temple in Seoul, South Korea, Wednesday, May 6, 2026. (Lee Jin-man/AP)

“The ordination of a robot signifies that technology must be used in accordance with the values of compassion, wisdom, and responsibility,” the order said in a statement shared with The New York Times. Officials added that the move symbolizes “new possibilities for the coexistence of humans and technology.”

Hong Min-suk, a manager at the order, told the publication that robots are “destined to collaborate with humans in every field,” suggesting it is only “natural” for them to participate in religious festivals.

The Jogye Order did not immediately respond to Fox News Digital’s request for comment.

Advertisement

Despite the temple’s optimistic outlook, the move has drawn criticism online. A video of Gabi’s pledge quickly surpassed one million views, with some users on X questioning whether a machine can meaningfully participate in religious practice.

Buddhist monks arrive at Washington National Cathedral in Washington, D.C., on Feb. 10, 2026, before participating in an interfaith ceremony during the final days of their 2,300-mile “Walk for Peace.” (Drew Angerer/AFP via Getty Images)

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

“As a Buddhist, I find this ridiculous and insulting,” one user wrote.

Gabi is expected to make its next public appearance at Seoul’s upcoming Lantern Festival on May 16-17, honoring the Buddha’s birthday.

Advertisement

Continue Reading

Technology

Live updates from Elon Musk and Sam Altman’s court battle over the future of OpenAI

Published

on

Live updates from Elon Musk and Sam Altman’s court battle over the future of OpenAI

Sam Altman and Elon Musk are facing off in a high-stakes trial that could alter the future of OpenAI and its most well-known product, ChatGPT. In 2024, Musk filed a lawsuit accusing OpenAI of abandoning its founding mission of developing AI to benefit humanity and shifting focus to boosting profits instead.

Elon Musk, his financial manager and Neuralink CEO, Jared Birchall, and OpenAI cofounder Greg Brockman have already testified before the jury. Now, on Wednesday, May 6th, Shivon Zilis, a former OpenAI board member who shares four children with Musk, is taking the stand, and the courtroom is seeing testimony from former OpenAI exec Mira Murati via video.

Microsoft CEO Satya Nadella is scheduled to appear on Monday, with OpenAI cofounder and former chief scientist Ilya Sutskever lined up to testify after that.

Musk was a cofounder of OpenAI and claims that Altman and Brockman tricked him into giving the company money, only to turn their backs on their original goal. However, OpenAI says that “This lawsuit has always been a baseless and jealous bid to derail a competitor” in a bid to boost Musk’s own SpaceX / xAI / X companies that have launched Grok as a competitor to ChatGPT.

Elon Musk — plaintiff, OpenAI cofounder and now CEO of rival xAI

Advertisement

Steven Molo — lead counsel for plaintiff

Jared Birchall — manager of Musk’s family office

Shivon Zilis — former OpenAI board member who shares multiple children with Musk

Sam Altman — defendant, CEO of OpenAI

William Savitt — lead counsel for defendant

Advertisement

Greg Brockman — president of OpenAI as well as a cofounder

Ilya Sutskever — former chief scientist at OpenAI and a cofounder

Yvonne Gonzalez Rogers — aka YGR, trial judge

Here’s all the latest on the trial between Musk and Altman:

Advertisement
Continue Reading
Advertisement

Trending