ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

A new breed of macOS malware, known as ClickFix, has emerged, targeting cryptocurrency wallets and draining funds from unsuspecting users. The attacks are noteworthy for their sophistication, leveraging a combination of social engineering and clever coding to evade detection.

ClickFix operates by masquerading as a legitimate software update, tricking victims into installing the malicious payload. Once inside, the malware exploits macOS’s built-in features to access sensitive information, including cryptocurrency wallet data. This is achieved through cross-domain privilege escalation (CDPE), which allows attackers to bypass security restrictions and move laterally across different domains within the system.

The malware’s primary goal is to drain funds from cryptocurrency wallets stored on infected machines. To do this, ClickFix searches for wallet addresses associated with popular exchanges like Coinbase and Binance, and then uses those credentials to transfer funds to attacker-controlled wallets. This process can be automated, making it difficult for users to detect the theft until it’s too late.

The attackers behind ClickFix have been using social media platforms to spread their malware, often targeting cryptocurrency enthusiasts and traders. These victims are likely unaware that clicking on a seemingly innocuous link or downloading a “software update” could compromise their wallets.

As the cybersecurity landscape continues to evolve, users must be vigilant against attacks like ClickFix. The fact that this malware is specifically designed to target cryptocurrency wallets highlights the growing threat of financial theft in the digital age. Users should exercise extreme caution when interacting with online platforms and software updates, and take regular backups of sensitive data to minimize potential losses.

To stay safe from such threats, users should prioritize robust cybersecurity practices, including keeping their operating systems and applications up-to-date, using reputable antivirus solutions, and being cautious when interacting with unfamiliar links or downloads. Regularly monitoring account activity and wallet balances can also help detect suspicious transactions in a timely manner.


Source: The Hacker News — 2026-08-07