VMTech
Discuss a project

ClickFix campaign delivers macOS stealer with wallet-draining routine

ClickFix campaign delivers macOS stealer with wallet-draining routine

ClickFix-style social-engineering attacks are being used to install a Go-based stealer on macOS that can collect browser passwords, Apple iCloud Keychain data and cached credentials, while also transferring cryptocurrency from victims’ wallets. Huntress researcher Andrew Brandt said the malware can slowly deplete accounts by siphoning assets to wallets controlled by the threat actor.

The infection begins when a victim is persuaded to paste a ClickFix command into the Terminal application. That command runs a Bash profiler and loader which gathers extensive information about the host before retrieving a Mach-O payload matched to the Mac’s CPU architecture.

Credential theft paired with wallet transfers

Once installed, the Go-based payload can capture browser-stored passwords, Apple Keychain data and cached credentials, then send them to a remote server operated by the attacker. It also attempts to obtain elevated privileges through a fake prompt that cites an “unexpected system error” and claims damaged system files need to be restored.

The notable component is a routine named DRAIN. It checks whether a cryptocurrency wallet contains funds and, if it does, redirects a portion or the whole balance to an attacker-controlled wallet. Separate versions of the function target Bitcoin, Litecoin, Dogecoin, Monero, Ethereum and Ripple’s XRP.

Huntress said this is the first malware it has observed that could be used to remove less than the entire value of a wallet. The code includes distinct functions to determine the value of 1% of a wallet’s contents for the cryptocurrency being targeted, making incremental theft possible.

ClickFix remains a cross-platform delivery method

The campaign illustrates how ClickFix lures turn user action into the initial execution step. In the broader pattern of ClickFix attack chains and AI agent incidents, attackers have used deceptive verification instructions to induce users to run commands, rather than relying solely on an exploit to start an infection.

The servers staging the malicious payloads and the command-and-control infrastructure were linked to Aeza Group, a Russian bulletproof hosting provider sanctioned by the United States, the United Kingdom and Australia for facilitating bad actors.

Other recently reported ClickFix activity includes a macOS campaign distributing MacSync and Atomic Stealer through look-alike domains, and Windows variants that abuse legitimate components such as Program Compatibility Assistant, PowerShell, WMI, WebDAV and rundll32.exe. Another campaign used WebAssembly modules and SVG steganography to assemble a ClickFix lure while evading network-level detection.

Business implication

Organizations should treat requests to paste commands into Terminal or a Run window as a high-risk social-engineering signal, restrict unapproved script execution, and require independent review of cryptocurrency transactions so stolen credentials alone cannot authorize a transfer.

#cybersecurity#macossecurity#clickfix#cryptowallets
Open analytics
On the site 0 views
min read 3 07.08.2026
Instagram

ClickFix campaign delivers macOS stealer with wallet-draining routine

Open the post on Instagram ↗