ClickFix attack pushes macOS infostealer for crypto theft attacks

A sophisticated Go-based malware is being delivered via ClickFix attacks targeting macOS users, with the goal of stealing cryptocurrency assets and sensitive data. The malicious payload, which has been dubbed an “infostealer” due to its ability to extract confidential information from compromised systems, can also redirect transactions with various cryptocurrencies.

Security researchers at Huntress discovered the malware after responding to a ClickFix incident, where a user received an email with a link to a page instructing them to run a command in Terminal. The downloaded Bash script acted as a profiler and malware loader, collecting system information and retrieving a Mach-O payload that matched the victim’s processor architecture. This payload was then copied to a directory named after the trustd process, which is responsible for validating cryptographic certificates and code signatures.

The infostealer payload checks for files containing credentials, including browser password databases, Apple Keychain data, and cached credentials in browser cookies. But what’s particularly concerning about this malware is its ability to modify cryptocurrency transactions before they are signed, allowing it to redirect a percentage of the funds to the attacker’s account. According to Huntress, this is the first time they’ve analyzed a crypto drainer that doesn’t empty victims’ wallets entirely but can instead remove less than the total amount.

The targeted cryptocurrency assets include Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple’s XRP. The malware communicates with shared IP addresses in Autonomous System (AS) 210644, which is operated by a Russian corporation known as Aeza Group. This company has been sanctioned by the US and UK for providing bulletproof hosting services to ransomware groups.

The ClickFix attack is a sobering reminder that even seemingly legitimate tools can be used to deliver malicious payloads. As security teams continue to log 54% of successful attacks but alert on only 14%, it’s clear that more needs to be done to stay ahead of threats. One key takeaway from this incident is the importance of testing every layer of defense before attackers do.

By regularly conducting breach and attack simulation tests, organizations can validate their SIEM and EDR rules and ensure that potential threats are not slipping through detection. By taking proactive measures like these, security teams can reduce the risk of falling victim to sophisticated attacks like the one described here.


Source: Bleeping Computer — 2026-08-06