Russian threat actors are using the ClickFix method to steal passwords and drop infostealer malware on macOS targets.CloudSek researchers found spoofed websites mimicking Spectrum to trick visitors into running malicious commands on their devices.The attackers prompt victims to go through a fake verification process and then run a command that delivers the malware that steals sensitive data.The campaign is attributed to Russian-speaking cybercriminals, targeting both consumer and corporate users through social engineering attacks.