Ethical Hacking News
ClickFix-style attacks are being used to deliver a Go-based malware that can steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The malware can drain crypto wallet contents into accounts under the threat actor's control.
A new type of malware targeting macOS systems is stealing cryptocurrency assets and draining their contents into accounts under threat actors' control.The malware uses a "ClickFix-style attack" to deliver a Go-based stealer that captures browser passwords, Apple iCloud Keychain data, and cached credentials.The malware can slowly deplete cryptocurrency accounts by siphoning funds into attacker-controlled wallets through a "DRAIN" routine.The server staging malicious payloads and the command-and-control (C2) server link back to Aeza Group, a Russian bulletproof hosting provider sanctioned for facilitating bad actors.Other stealer campaigns, including Lumma Stealer and Remus, have been discovered, highlighting a growing trend of ClickFix-style attacks on macOS systems.
A recent report by Huntress security researcher Andrew Brandt has shed light on a new type of malware that is being used to steal cryptocurrency assets and drain their contents into accounts under the control of threat actors. The malware, which is designed to target macOS systems, uses a technique called "ClickFix-style attacks" to deliver a Go-based stealer that can capture browser passwords, Apple iCloud Keychain data, and cached credentials.
The ClickFix-style attack involves pasting a malicious command into the Terminal app, triggering the execution of a Bash profiler/loader that collects extensive system details. The Bash profiler/loader then retrieves a Mach-O payload that matches the victim's processor architecture, which is a Go-based stealer that can capture browser passwords, Apple iCloud Keychain data, and cached credentials and transmit them to a remote server operated by the threat actor.
What makes this malware particularly noteworthy is its ability to slowly deplete cryptocurrency accounts, siphoning their contents into accounts under the control of the threat actor. The malware contains a "DRAIN" routine that checks if a cryptocurrency wallet holds funds, and if so, redirects a chunk or all of it to an attacker-controlled wallet.
The server staging the malicious payloads and the command-and-control (C2) server all link back to infrastructure belonging to Aeza Group, a Russian bulletproof hosting provider that has been sanctioned by the U.S., the U.K., and Australia for facilitating bad actors. This highlights the growing threat of cybercrime in the cryptocurrency space.
The report also notes that the malware is part of a larger trend of ClickFix-style attacks being used to distribute malicious software on macOS systems. These attacks often involve pasting a malicious command into the Terminal app, triggering the execution of a Bash profiler/loader that collects extensive system details and retrieves a Mach-O payload that matches the victim's processor architecture.
In addition to the new malware, the report also highlights two other stealer campaigns that have been discovered in recent weeks. One of these campaigns delivers Lumma Stealer via files disguised as 1080p WEBRip and Blu-ray releases of The Odyssey, while another campaign uses cracked software and pirated game lures hosted on fake websites to drop Remus, a 64-bit variant of Lumma Stealer.
The findings of this report are significant because they highlight the growing threat of cybercrime in the cryptocurrency space. As more people begin to use cryptocurrencies, the risk of theft and exploitation increases. It is essential for users to take steps to protect themselves from these types of attacks, such as using strong passwords, keeping their software up to date, and being cautious when clicking on links or downloading attachments.
Furthermore, the report suggests that the use of legitimate-but-compromised websites can be used to evade network-level detection. The activity uses injected malicious JavaScript that builds a wasm module that exports URLs from which the SVG files are downloaded to construct the ClickFix URL. This final ClickFix URL is then dropped onto the DOM with a script tag to display the fake verification page.
The report also notes that the malware contains separate functions to determine just how much 1% of the wallet's contents is worth, depending on which cryptocurrency the malware targets. While this may not be a brand new feature, it is the first time we have seen malware capable of emptying a cryptocurrency wallet that could be used to remove any less than the entire wallet's value.
In conclusion, the ClickFix attacks that are being used to deliver macOS stealers are a significant threat to users in the cryptocurrency space. The use of legitimate-but-compromised websites and the ability to evade network-level detection make these types of attacks particularly concerning. It is essential for users to take steps to protect themselves from these types of attacks, such as using strong passwords, keeping their software up to date, and being cautious when clicking on links or downloading attachments.
Related Information:
https://www.ethicalhackingnews.com/articles/ClickFix-Attacks-Deliver-macOS-Stealer-That-Can-Drain-Crypto-Wallets-ehn.shtml
https://thehackernews.com/2026/08/clickfix-attacks-deliver-macos-stealer.html
Published: Fri Aug 7 15:18:45 2026 by llama3.2 3B Q4_K_M