- Cybercriminals are using sponsored ads on Twitter to impersonate the macOS DynamicLake application.
- The campaign uses the ClickFix technique to force the execution of malicious commands in the computer's Terminal.
- The infected software is the powerful Atomic Stealer, capable of stealing passwords, files, and cryptocurrency wallets.
- Fraud spreads even through verified accounts, managing to bypass the platform's security controls.
Navigating social media today requires extreme caution, especially when we encounter content that appears official but conceals very dubious intentions. A dangerous cybercrime campaign has recently been detected on the X platform, formerly Twitter, where attackers are buying advertising space for distributing malware Designed specifically for Apple computer users, the trap is so cleverly crafted that even the most cautious users could fall for it if they don't pay attention to the small details in the URL.
The problem is that these ads don't appear as suspicious messages from unknown accounts; instead, they blend seamlessly into the legitimate advertising we see daily on our news feeds. Researchers at Jamf Threat Labs have raised concerns after discovering that these promoted tweets are... silently infecting MacBook computersTaking advantage of the trust generated by seeing a sponsored ad on such a prominent social network. This isn't just annoying spam; it's a real threat that jeopardizes the privacy of those seeking to enhance their macOS experience.
DynamicLake spoofing and the ClickFix technique

The main hook in this scam is an application called DynamicLake, a fairly popular tool that allows users to emulate the iPhone's 'Dynamic Island' on Apple computers. The criminals have completely cloned the aesthetics, logos, and screenshots of the original app so that The ad looks one hundred percent real. to the eyes of any user. However, when clicking on the link, instead of going to the official website, unsuspecting users are redirected to a fraudulent domain that differs by only a couple of letters from the legitimate one, something that usually goes unnoticed in a quick scan.
Once the victim enters the fake website, what security experts call the 'ClickFix' technique is activated. In this scenario, the page displays a supposed installation error and tricks the user into opening the Terminal application on their Mac and Paste a direct execution commandThis is the most critical part, because by doing so you are giving the system permission to download and install malicious code without it going through any browser security filters, which greatly facilitates the hackers' work.
Atomic Stealer: The silent thief of your data

What actually gets installed after running that command isn't a visual upgrade for your Mac, but rather a variant of the dreaded Atomic Stealer malware (also known as AMZ). This program is designed to run in the background and has a voracious appetite for personal information, similar to how other malware operates. the Sturnus Trojan for stealing passwordsAccording to several cybersecurity firms, this virus is capable of extract passwords saved in the keychainbrowser session cookies, confidential system files, and, most lucrative for attackers, cryptocurrency wallet keys.
The effectiveness of this software lies in its discretion, since once the computer is infected, the user doesn't notice any slowdowns or strange behavior while their data is being transferred to external servers. That's why it's vital to remember that Commands should never be executed In the Apple ecosystem, it's always wise to use the Mac App Store or manually verify that the developer is properly certified by Apple before installing anything.
Verified accounts and the failure in X controls

What's most disturbing about this case is that the campaign was launched using accounts that had the blue X verification badge. Apparently, the cybercriminals took control of profiles with a significant number of followers to lend an air of legitimacy to their ads. Because these were verified accounts, they were flagged by the automated advertising review systems of Elon Musk's social network. They did not detect the malicious linkThis allowed the ad to reach thousands of people in a very short time. The owner of one of these accounts didn't even know their profile was being used to scam people, which proves that no one is safe.
This type of incident highlights the fact that the ad filtering process on major social media platforms is failing across the board. It's not the first time something similar has happened, as similar cases have been seen on Google Ads, but the fact that X is exploiting the visibility of verified profiles makes it especially dangerous. Ultimately, it's the responsibility of not falling into this trap. falls directly on the userwho should systematically suspect any download that does not come from the developer's official channel, no matter how beautiful and sponsored the advertisement presented on screen may be.
Absolute security on the internet doesn't exist, but using common sense is the best defense we can have against these hackers. If an ad asks us to take strange steps to install a simple application, it's best to close the tab and find the tool ourselves on trusted websites. Remember that keeping your operating system updated and not trusting appearances on social media are key to preventing these attacks. our personal data end up in the wrong hands because of a simple click made wrong at the worst possible moment.

