July 5, 2026
- Verified X ad pushes Mac malware plus a browser-based M365 token thief. A sponsored post from a verified account impersonated the DynamicLake utility and redirected to a lookalike domain instructing users to paste a Terminal command, delivering an Atomic Stealer variant (tracked as MacSync, with DigitStealer in some cases). The same report flags ConsentFix, a ClickFix-style trick that steals Microsoft 365 session tokens through the browser — no malware, no password. Malwarebytes · Threat Activity