{"id":2282,"date":"2026-08-07T21:20:04","date_gmt":"2026-08-07T21:20:04","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2282"},"modified":"2026-08-07T21:20:04","modified_gmt":"2026-08-07T21:20:04","slug":"clickfix-attacks-deliver-macos-stealer-that-can-drain-crypto-wallets","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2282","title":{"rendered":"ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 07, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ Social Engineering<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiKQGTQ6AquoAvAeMWXXITPacYsdChgFUpg7MLwKkfb2AylEuwQTk9av5GqMSdgtsB_tr_6QC70DrJkEo02t-Wo67z1gumix6FKKlOPSWo4fLEUHCibBoTrf1zCdmn72ESzo5CzCKKEgyETZ0FeVD_3QLfCNit7vIwlMA7MmwGYg2JGbeYOBrjSHmOnfpWl\/s1700-e365\/macos.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.<\/p>\n<p>The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that&#8217;s compatible with the computer&#8217;s CPU architecture.<\/p>\n<p>\u00abWhile the malware payload is capable of stealing passwords, its most interesting function is its capability to slowly deplete cryptocurrency accounts, siphoning their contents into accounts under the threat actor&#8217;s control,\u00bb Huntress security researcher Andrew Brandt <a href=\"https:\/\/www.huntress.com\/blog\/mac-crypto-draining-malware\" target=\"_blank\">said<\/a>.<\/p>\n<p>The attack chain begins with pasting a ClickFix command into the Terminal app, triggering the execution of a Bash profiler\/loader that collects extensive system details and then retrieves a Mach-O payload that matches the victim&#8217;s processor architecture. The payload is a Go-based stealer that can capture browser passwords, Apple Keychain data, and cached credentials and transmit them to a remote server operated by the threat actor.<\/p>\n<p>Like other macOS stealers, the malware attempts to escalate privileges by prompting the victim to enter their system credentials via a fake prompt under the guise of an \u00abunexpected system error\u00bb and restoring damaged system files.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlocker-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh5OTk93vfDmhLLtqoMsx4w59kseqsUysQ92SKB-S2vDoKsMmMfCCkx8AbG5MFzFvZ7rkzKd5LtgOCxlRF2FJ-0FArsVhpOnTMX31VBi9TX-z1Pgv9oSvXiT23KyDlxtVqI0dPRdMIuWc9fbNWgQF8CisKtMme0LpNr79b4wRaeDRxCjfGB8GsxfXa8Ltro\/s728-e100\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>What&#8217;s notable about the malware is that it also packs in a \u00abDRAIN\u00bb routine that checks if a cryptocurrency wallet holds funds, and if so, redirects a chunk or all of it to an attacker-controlled wallet. There exist multiple versions of the same function based on the cryptocurrency being targeted. This includes Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple&#8217;s XRP.<\/p>\n<p>\u00abWhile this may not be a brand new feature, it&#8217;s the first time we have seen malware capable of emptying a cryptocurrency wallet that could be used to remove any less than the entire wallet&#8217;s value,\u00bb Huntress said. \u00abThe malware contained separate functions to determine just how much 1% of the wallet&#8217;s contents is worth, depending on which cryptocurrency the malware targets.\u00bb<\/p>\n<p>The server staging the malicious payloads and the command-and-control (C2) server all link back to infrastructure belonging to <a href=\"https:\/\/thehackernews.com\/2025\/07\/us-sanctions-russian-bulletproof.html\" target=\"_blank\">Aeza Group, a Russian bulletproof hosting provider that has been sanctioned by the U.S., the U.K., and Australia for facilitating bad actors.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhVSRfBpsMCn4hZCk6089FFaZHX1qwvDHjuAzLaiIFbpP04CEhJprvlwAbRuRgn3Zlx3HlAenH9pGg6a4Kbf_TZVT7yBH9ilRfvzALXwZdXbr6QewjZYy0KzEXtzR1Pq9sm_OMOqA8jmpD-TMybBCuBrx_QWjwJxXTkqmXRiqMByi0JAwtHDru_UM6xZ6d8\/s1700-e365\/drain.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhVSRfBpsMCn4hZCk6089FFaZHX1qwvDHjuAzLaiIFbpP04CEhJprvlwAbRuRgn3Zlx3HlAenH9pGg6a4Kbf_TZVT7yBH9ilRfvzALXwZdXbr6QewjZYy0KzEXtzR1Pq9sm_OMOqA8jmpD-TMybBCuBrx_QWjwJxXTkqmXRiqMByi0JAwtHDru_UM6xZ6d8\/s1700-e365\/drain.png\" alt=\"\" border=\"0\" data-original-height=\"578\" data-original-width=\"776\"\/><\/a><\/div>\n<p>The disclosure comes as a number of ClickFix attacks have been reported in recent weeks &#8211;<\/p>\n<ul>\n<li>A macOS ClickFix campaign distributing <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/08\/05\/macos-clickfix-campaign-learned-hide\/\" target=\"_blank\">MacSync and Atomic Stealer<\/a> malware that uses a cluster of look-alike domains and implements a server-side browser-fingerprinting and hardware validation gate to conditionally serve the lures only to those visitors whose environment appears consistent with a genuine macOS browser, while blocking crawlers, sandboxes, and some automated analysis tools.<\/li>\n<li>A ClickFix variant that abuses <a href=\"https:\/\/github.com\/PaloAltoNetworks\/Unit42-timely-threat-intel\/blob\/main\/2026-08-05-New-Clickfix-Variant.txt\" target=\"_blank\">Program Compatibility Assistant<\/a> (\u00abpcalua.exe\u00bb), a legitimate Windows binary, as a launcher to bypass parent-process heuristics. \u00abThe victim is tricked (via a ClickFix lure) into pasting a crafted command that spawns PowerShell, uses WMI to create cmd.exe, mounts a remote WebDAV share, and loads a malicious DLL through rundll32.exe,\u00bb Palo Alto Networks Unit 42 said. \u00abThe WebDAV share is exposed over HTTPS via CDN-fronted infrastructure at a per-victim tokenized URL (UUIDv4 path) used to deliver malicious DLL. Once loaded, the DLL is leveraged to deploy infostealer capabilities on the compromised host.\u00bb<\/li>\n<li>A ClickFix campaign that uses <a href=\"https:\/\/github.com\/PaloAltoNetworks\/Unit42-timely-threat-intel\/blob\/main\/2026-07-16-ClickFix-campaign-using-wasm-and-steganography.txt\" target=\"_blank\">on-the-fly WebAssembly (wasm) module instantiation<\/a> and steganography through SVG images to evade network-level detection. The activity uses legitimate-but-compromised websites to run injected malicious JavaScript that builds a wasm module that exports URLs from which the SVG files are downloaded to construct the ClickFix URL. \u00abThis final ClickFix URL is then dropped onto the DOM with a script tag to display the fake verification page,\u00bb Unit 42 said. \u00abThe fake verification page presents a checkbox. When the checkbox is clicked, the page presents instructions to paste content into a Run window.\u00bb<\/li>\n<\/ul>\n<p>The findings also coincide with the discovery of two other stealer campaigns, one which delivers Lumma Stealer via files <a href=\"https:\/\/www.bitdefender.com\/en-us\/blog\/hotforsecurity\/the-odyssey-piracy-lumma-stealer\" target=\"_blank\">disguised<\/a> as 1080p WEBRip and Blu-ray releases of The Odyssey, a newly released movie adaptation of Homer&#8217;s ancient Greek epic poem of the same name, and another which uses <a href=\"https:\/\/github.com\/PaloAltoNetworks\/Unit42-timely-threat-intel\/blob\/main\/2026-07-30-Remus-Info-Stealer-Uses-Blockchain-Anchored-C2.txt\" target=\"_blank\">cracked software and pirated game lures<\/a> hosted on fake websites via SEO poisoning to drop <a href=\"https:\/\/flashpoint.io\/blog\/remus-stealer-a-new-not-so-new-infostealer\/\" target=\"_blank\">Remus<\/a>, a 64-bit variant of Lumma Stealer.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 07, 2026Malware \/ Social Engineering ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2283,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[24,225,143,529,2455,421,478,617],"class_list":["post-2282","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-attacks","tag-clickfix","tag-crypto","tag-deliver","tag-drain","tag-macos","tag-stealer","tag-wallets"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2282","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2282"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2282\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2283"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2282"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2282"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2282"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}