Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

The Hacker News by The Hacker News
August 7, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananAug 07, 2026Malware / Social Engineering

ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.

The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that’s compatible with the computer’s CPU architecture.

“While the malware payload is capable of stealing passwords, its most interesting function is its capability to slowly deplete cryptocurrency accounts, siphoning their contents into accounts under the threat actor’s control,” Huntress security researcher Andrew Brandt said.

The attack chain begins with pasting a ClickFix command into the Terminal app, triggering the execution of a Bash profiler/loader that collects extensive system details and then retrieves a Mach-O payload that matches the victim’s processor architecture. The payload is a Go-based stealer that can capture browser passwords, Apple Keychain data, and cached credentials and transmit them to a remote server operated by the threat actor.

Like other macOS stealers, the malware attempts to escalate privileges by prompting the victim to enter their system credentials via a fake prompt under the guise of an “unexpected system error” and restoring damaged system files.

What’s notable about the malware is that it also packs in a “DRAIN” routine that checks if a cryptocurrency wallet holds funds, and if so, redirects a chunk or all of it to an attacker-controlled wallet. There exist multiple versions of the same function based on the cryptocurrency being targeted. This includes Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple’s XRP.

“While this may not be a brand new feature, it’s the first time we have seen malware capable of emptying a cryptocurrency wallet that could be used to remove any less than the entire wallet’s value,” Huntress said. “The malware contained separate functions to determine just how much 1% of the wallet’s contents is worth, depending on which cryptocurrency the malware targets.”

The server staging the malicious payloads and the command-and-control (C2) server all link back to infrastructure belonging to Aeza Group, a Russian bulletproof hosting provider that has been sanctioned by the U.S., the U.K., and Australia for facilitating bad actors.

The disclosure comes as a number of ClickFix attacks have been reported in recent weeks –

  • A macOS ClickFix campaign distributing MacSync and Atomic Stealer malware that uses a cluster of look-alike domains and implements a server-side browser-fingerprinting and hardware validation gate to conditionally serve the lures only to those visitors whose environment appears consistent with a genuine macOS browser, while blocking crawlers, sandboxes, and some automated analysis tools.
  • A ClickFix variant that abuses Program Compatibility Assistant (“pcalua.exe”), a legitimate Windows binary, as a launcher to bypass parent-process heuristics. “The victim is tricked (via a ClickFix lure) into pasting a crafted command that spawns PowerShell, uses WMI to create cmd.exe, mounts a remote WebDAV share, and loads a malicious DLL through rundll32.exe,” Palo Alto Networks Unit 42 said. “The WebDAV share is exposed over HTTPS via CDN-fronted infrastructure at a per-victim tokenized URL (UUIDv4 path) used to deliver malicious DLL. Once loaded, the DLL is leveraged to deploy infostealer capabilities on the compromised host.”
  • A ClickFix campaign that uses on-the-fly WebAssembly (wasm) module instantiation and steganography through SVG images to evade network-level detection. The activity uses legitimate-but-compromised websites to run injected malicious JavaScript that builds a wasm module that exports URLs from which the SVG files are downloaded to construct the ClickFix URL. “This final ClickFix URL is then dropped onto the DOM with a script tag to display the fake verification page,” Unit 42 said. “The fake verification page presents a checkbox. When the checkbox is clicked, the page presents instructions to paste content into a Run window.”

The findings also coincide with the discovery of two other stealer campaigns, one which delivers Lumma Stealer via files disguised as 1080p WEBRip and Blu-ray releases of The Odyssey, a newly released movie adaptation of Homer’s ancient Greek epic poem of the same name, and another which uses cracked software and pirated game lures hosted on fake websites via SEO poisoning to drop Remus, a 64-bit variant of Lumma Stealer.



Source link

The Hacker News

The Hacker News

Next Post
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

Recommended.

Napster Partners with Fenerbahçe SK to Launch 3D, AI-Powered Virtual Store For its Millions of Global Fans – Exclusively Through Fenerium

Napster Partners with Fenerbahçe SK to Launch 3D, AI-Powered Virtual Store For its Millions of Global Fans – Exclusively Through Fenerium

August 27, 2025
IMF’s Georgieva urges China to speed up ‘long-overdue’ shift away from relying on exports for growth, so as ‘not to provoke’ other countries

IMF’s Georgieva urges China to speed up ‘long-overdue’ shift away from relying on exports for growth, so as ‘not to provoke’ other countries

December 10, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

May 1, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026
30 Notable IT Executive Moves: April 2026

30 Notable IT Executive Moves: April 2026

May 11, 2026
The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

April 6, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio