Close Menu
NCIJ Network NCIJ Network
    What's Hot

    ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

    September 23, 2026

    OpenAI Launches GPT-6 Sol and Luna Minutes After Anthropic Drops Claude Opus 5.5

    September 23, 2026

    The Solar System chose fire over ice from the very beginning

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
    • OpenAI Launches GPT-6 Sol and Luna Minutes After Anthropic Drops Claude Opus 5.5
    • The Solar System chose fire over ice from the very beginning
    • Competing Climate Visions Clash at UN General Assembly
    • It’s easy to ignore the Lib Dems, but they could soon hold the balance of power | Rafael Behr
    • Trump rallies Shield of the Americas coalition against drug cartels | United Nations News
    • Das Neukölln-Problem der Linken – POLITICO
    • Critics of UK government’s economic forecaster are ‘shooting the messenger’, say MPs | Office for Budget Responsibility
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ClickFix attack pushes macOS infostealer for crypto theft attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 7, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials.

    ​The malware can intercept and redirect transactions with various cryptocurrencies. Although it can empty wallets entirely, it can also calculate the total value of a transaction to determine how much to divert to the attacker.

    Security researchers at Managed Detection and Response (MDR) services company Huntress discovered the payload after responding to a ClickFix incident.

    image

    The targeted user received an email with a link to a page instructing them to run a command in Terminal.

    This downloaded a Bash script acting as a profiler and malware loader that collected system information (e.g., CPU, RAM) and retrieved a Mach-O payload that matched the victim system’s processor architecture.

    The profiler also identified the account name for the currently logged-in user and created a directory named after trustd, the macOS process responsible for validating cryptographic certificates and code signatures.

    It copied the infostealing and crypto-draining payload to the directory as com.apple.verified and removed the com.apple.quarantine extended attribute to prevent Gatekeeper from treating the file as quarantined and showing a security alert when executed.

    According to Huntress’ analysis, the malware establishes persistence and increases privileges by collecting system credentials via a fake error created using the osascript utility.

    Fake dialog box prompting for admin password
    Fake dialog box prompting for admin password
    source: Huntress

    The stealer payload checks the storage for files containing credentials, identified both by name and their extension.

    “Browser password databases, the Apple Keychain, and cached credentials in browser cookies are all targeted,” Huntress says.

    However, the Go-based malware also includes code that modifies cryptocurrency transactions before they are signed, and can be configured to redirect to the attacker only a percentage of the funds.

    Malware can be configured to drain a certain crypto amount
    Malware can be configured to drain a certain crypto amount
    source: Huntress

    Huntress says that it is the first time they analyzed a crypto drainer that did not empty victims’ wallets but could remove less than the total amount.

    Additionally, the researchers observed separate functions that determined the value of 1% of the wallet’s content, depending on the cryptocurrency type.

    Among the targeted cryptocurrency assets are Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple’s XRP.

    According to Huntress, the malware communicates to shared IP addresses in Autonomous System (AS) 210644, which is “operated by a Russian corporation known as the Aeza Group.”

    The company and individuals affiliated with it have been sanctioned by the US and the UK for providing bulletproof hosting services to ransomware groups.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    attack attacks ClickFix Crypto infostealer macOS pushes theft
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

    Check Point warns of Management Server zero-day exploited in attacks

    Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

    CME Expands Crypto Futures Lineup With Bitcoin Cash and Uniswap

    Only 13% of OT Network Segments Are Fully Isolated: Analysis

    Democrats ‘chose visceral hatred for’ Donald Trump over crypto Clarity Act, Lummis says

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

    September 23, 2026

    OpenAI Launches GPT-6 Sol and Luna Minutes After Anthropic Drops Claude Opus 5.5

    September 23, 2026

    The Solar System chose fire over ice from the very beginning

    September 23, 2026

    Competing Climate Visions Clash at UN General Assembly

    September 23, 2026
    Latest Posts

    COLDCARD security audit phishing attack installs remote access tool

    August 5, 2026

    Reddit aims to make ‘karma’ less important for first-time posters with shift to AI moderation tools

    August 5, 2026

    Right turn on green: is the Telegraph changing its tune on the climate? | Daily Telegraph

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

    September 23, 2026

    OpenAI Launches GPT-6 Sol and Luna Minutes After Anthropic Drops Claude Opus 5.5

    September 23, 2026

    The Solar System chose fire over ice from the very beginning

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.