Hackers Abuse Google Sites to Host Fake OpenAI Codex Download Pages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Cybercriminals are using Google Sites to host fake download pages for OpenAI Codex, turning a familiar search into a malware trap.

The campaign targets macOS users and relies on paid search placements to steer them toward a convincing but fraudulent installer page.

The page does not simply deliver a harmful app. It tells visitors to copy a command, open Terminal, and run it themselves.

That approach, known as ClickFix, shifts the final execution step to the victim and can bypass the suspicion normally raised by an unexpected download.

Cato analysts identified the activity after tracking sponsored results for searches including “codex macos download.”

Cato said in a report shared with Cyber Security News (CSN) that the chain has strong overlap with Atomic macOS Stealer, also called AMOS, delivery activity. The risk reaches beyond one spoofed developer tool.

Sponsored result impersonating a Codex download (Source - CATO)
Sponsored result impersonating a Codex download (Source – CATO)

By combining a paid advertisement, a legitimate Google-hosted page, and a recognised software brand, operators build a route that looks trustworthy at every early stage. Similar malicious Google Ads campaigns have shown how paid search can expose macOS users to harmful software.

Hackers Abuse Google Sites

The sponsored result appeared above the genuine result and sent visitors to a Google Sites page designed to resemble a Codex download portal.

It displayed download choices for macOS and Linux, although researchers observed active payload delivery only for macOS users. Google Sites acted as the visible front door rather than the place serving the main malicious content.

Fake Codex download page hosted on Google Sites (Source – CATO)

The page loaded an attacker-controlled iframe, allowing the operators to retain a trusted-looking Google address while changing the content behind it. This separation also makes takedowns and analysis more difficult.

One newer infrastructure set used a useful evasion trick. Its live ClickFix content was placed at “/codexx/”, while the expected “/codex/” address returned a harmless-looking product page.

Visitors using a non-macOS device also received benign content, frustrating automated scanners and investigators. The campaign shows why search results should not be treated as proof of authenticity.

Users should obtain developer tools through verified vendor channels, inspect the destination before downloading, and never paste an unfamiliar installation command into Terminal. The warning is especially relevant after fake Node.js installer ads used sponsored search results to reach potential victims.

ClickFix Chain Delivers macOS Payload

The fake installer starts with a legitimate-looking Codex npm command, then hides a Base64-encoded address that retrieves a script and pipes it into zsh.

The victim sees what appears to be a normal setup step, but running the command begins a three-stage delivery chain. The first script decodes an embedded component, which produces a second script.

That stage records an “event=pasted” signal, downloads the final Mach-O file to “/tmp/helper”, clears its extended attributes with “xattr -c”, marks it executable, and launches it. Removing those attributes can reduce the warning context associated with downloaded files.

Researchers found overlap with AMOS delivery methods, including encoded curl loaders, hidden zsh stages, telemetry before payload retrieval, and the same temporary staging location.

Trusted services and user action form one malware-delivery chain (Source - CATO)
Trusted services and user action form one malware-delivery chain (Source – CATO)

It does not prove that every final payload is identical, but it gives defenders meaningful evidence for incident hunting. Recent macOS ClickFix attack reports illustrate the broader threat from prompts that persuade users to run commands.

Security teams should review logs for shell commands that decode Base64 data, curl piped to zsh, new executables in “/tmp/helper”, attribute removal, and unusual outbound requests immediately after Terminal activity.

Network controls should also block the listed lure, iframe, telemetry, and payload-delivery infrastructure, while detections should combine these behavioural signs instead of relying on a single domain.

The operators have already reused portions of their infrastructure while rotating domains, payload locations, and brands, including a related Claude Code-themed landing page.

That flexibility means the indicators below are best used with behavioural monitoring. Users can further reduce exposure by treating sponsored results cautiously, checking the publisher’s official download path, and rejecting any page that asks them to paste a command as a “fix.”

Indicators of compromise (IoCs):-

Type Indicator Description
Google Sites lure sites[.]google[.]com/view/cod… Fake Codex Google Sites lure, rendered in truncated form in the supplied source PDF
Domain bright-links[.]com Attacker-controlled iframe host
Domain trekmesh15[.]com Script and payload host
Domain grove-12[.]com Telemetry host
URL trekmesh15[.]com/curl/ad4e2 First-stage script
URL grove-12[.]com/api/metrics/ru… Execution telemetry endpoint, rendered in truncated form in the supplied source PDF
URL trekmesh15[.]com/zyeMb6slon_3VWVlkSkdiJurcyhY5cFNtchnavRnMgU/jetbrains/update Version 1 payload-retrieval endpoint
SHA-256 15d34ae7f341e105e240d9f0f… Packed Mach-O sample hash, rendered in truncated form in the supplied source PDF
SHA-256 333af1bb9303296fa81d5b166… x86_64 Mach-O sample hash, rendered in truncated form in the supplied source PDF
SHA-256 e5008cd226c57640607bcfea… ARM64 Mach-O sample hash, rendered in truncated form in the supplied source PDF
Google Sites lure sites[.]google[.]com/view/cdx… Google Sites lure for Infrastructure Set 2, rendered in truncated form in the supplied source PDF
Domain swiftsaverfin[.]com Attacker-controlled iframe host
URL swiftsaverfin[.]com/codexx/ Active ClickFix path
Domain aspencore18[.]com Script and payload host
Domain atlas-compass[.]com Telemetry host
URL aspencore18[.]com/curl/0v95 First-stage script
URL atlas-compass[.]com/api/me… Execution telemetry endpoint, rendered in truncated form in the supplied source PDF
URL aspencore18[.]com/2kqYRM0 Payload-retrieval endpoint
SHA-256 1f252e8110474ac65d5b7e3ea… Packed Mach-O sample hash, rendered in truncated form in the supplied source PDF
SHA-256 2bac3e8c223dafaf53540a5a… ARM64 Mach-O sample hash, rendered in truncated form in the supplied source PDF
SHA-256 e4e078458c025e0905d94f6… x86_64 Mach-O sample hash, rendered in truncated form in the supplied source PDF
Google Sites lure sites[.]google[.]com/view/cdx-off-page New Google Sites lure reusing earlier iframe infrastructure
Domain grove-satin[.]com Telemetry host
URL grove-satin[.]com/api/metrics… Execution telemetry endpoint, rendered in truncated form in the supplied source PDF
Domain quill-flint[.]com Script and payload host
URL quill-flint[.]com/curl/2h0w4vt First-stage script
URL quill-flint[.]com/zyeMb6slon_3VWVlkSkdiJurcyhY5cFNtchnavRnMgU/jetbrains/updateAll Version 3 payload-retrieval endpoint
SHA-256 684d4875a60e832c6993bb0… Packed Mach-O sample hash, rendered in truncated form in the supplied source PDF
SHA-256 9c3a28c5b8b9ced508786aa… ARM64 Mach-O sample hash, rendered in truncated form in the supplied source PDF
SHA-256 95d5ae5e87b4eae733655f6f… x86_64 Mach-O sample hash, rendered in truncated form in the supplied source PDF
Domain parentpreneurx[.]com Claude Code phishing landing page
Domain vine-96[.]com Script and payload host
URL vine-96[.]com/curl/iojaglaf/t1f First-stage script
URL vine-96[.]com/N_8qoQC3gm Payload-retrieval endpoint
SHA-256 fcb74c3c5134a97b5bc90b2e… Packed Mach-O sample hash, rendered in truncated form in the supplied source PDF
SHA-256 48db5d715c583b4495ee1e30… ARM64 Mach-O sample hash, rendered in truncated form in the supplied source PDF
SHA-256 1f252b86edddda142a69cf90… x86_64 Mach-O sample hash, rendered in truncated form in the supplied source PDF

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Hackers Abuse Google Sites to Host Fake OpenAI Codex Download Pages appeared first on Cyber Security News.