Close Menu
NCIJ Network NCIJ Network
    What's Hot

    What to do when your Waymo holds up a Secret Service motorcade

    September 23, 2026

    Pornhub age checks investigated by Ofcom

    September 23, 2026

    MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • What to do when your Waymo holds up a Secret Service motorcade
    • Pornhub age checks investigated by Ofcom
    • MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
    • Coin Metrics revises 19 months of ETF wallet data but by how much?
    • Risk of Hydrazine Use Following Freeze–Thaw Exposure
    • Asphalt Company Alleges Operative Who Posed as a Project Opponent Committed Fraud
    • Expro lines up 14-well Canadian offshore life-extension campaign
    • Could we be about to see the end of northern English dialects? My experience – and the science – says aye | Zahaan Bharmal
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 8, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 07, 2026Malware / Social Engineering

    ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.

    The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that’s compatible with the computer’s CPU architecture.

    “While the malware payload is capable of stealing passwords, its most interesting function is its capability to slowly deplete cryptocurrency accounts, siphoning their contents into accounts under the threat actor’s control,” Huntress security researcher Andrew Brandt said.

    The attack chain begins with pasting a ClickFix command into the Terminal app, triggering the execution of a Bash profiler/loader that collects extensive system details and then retrieves a Mach-O payload that matches the victim’s processor architecture. The payload is a Go-based stealer that can capture browser passwords, Apple Keychain data, and cached credentials and transmit them to a remote server operated by the threat actor.

    Like other macOS stealers, the malware attempts to escalate privileges by prompting the victim to enter their system credentials via a fake prompt under the guise of an “unexpected system error” and restoring damaged system files.

    Cybersecurity

    What’s notable about the malware is that it also packs in a “DRAIN” routine that checks if a cryptocurrency wallet holds funds, and if so, redirects a chunk or all of it to an attacker-controlled wallet. There exist multiple versions of the same function based on the cryptocurrency being targeted. This includes Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple’s XRP.

    “While this may not be a brand new feature, it’s the first time we have seen malware capable of emptying a cryptocurrency wallet that could be used to remove any less than the entire wallet’s value,” Huntress said. “The malware contained separate functions to determine just how much 1% of the wallet’s contents is worth, depending on which cryptocurrency the malware targets.”

    The server staging the malicious payloads and the command-and-control (C2) server all link back to infrastructure belonging to Aeza Group, a Russian bulletproof hosting provider that has been sanctioned by the U.S., the U.K., and Australia for facilitating bad actors.

    The disclosure comes as a number of ClickFix attacks have been reported in recent weeks –

    • A macOS ClickFix campaign distributing MacSync and Atomic Stealer malware that uses a cluster of look-alike domains and implements a server-side browser-fingerprinting and hardware validation gate to conditionally serve the lures only to those visitors whose environment appears consistent with a genuine macOS browser, while blocking crawlers, sandboxes, and some automated analysis tools.
    • A ClickFix variant that abuses Program Compatibility Assistant (“pcalua.exe”), a legitimate Windows binary, as a launcher to bypass parent-process heuristics. “The victim is tricked (via a ClickFix lure) into pasting a crafted command that spawns PowerShell, uses WMI to create cmd.exe, mounts a remote WebDAV share, and loads a malicious DLL through rundll32.exe,” Palo Alto Networks Unit 42 said. “The WebDAV share is exposed over HTTPS via CDN-fronted infrastructure at a per-victim tokenized URL (UUIDv4 path) used to deliver malicious DLL. Once loaded, the DLL is leveraged to deploy infostealer capabilities on the compromised host.”
    • A ClickFix campaign that uses on-the-fly WebAssembly (wasm) module instantiation and steganography through SVG images to evade network-level detection. The activity uses legitimate-but-compromised websites to run injected malicious JavaScript that builds a wasm module that exports URLs from which the SVG files are downloaded to construct the ClickFix URL. “This final ClickFix URL is then dropped onto the DOM with a script tag to display the fake verification page,” Unit 42 said. “The fake verification page presents a checkbox. When the checkbox is clicked, the page presents instructions to paste content into a Run window.”

    The findings also coincide with the discovery of two other stealer campaigns, one which delivers Lumma Stealer via files disguised as 1080p WEBRip and Blu-ray releases of The Odyssey, a newly released movie adaptation of Homer’s ancient Greek epic poem of the same name, and another which uses cracked software and pirated game lures hosted on fake websites via SEO poisoning to drop Remus, a 64-bit variant of Lumma Stealer.

    attacks ClickFix Crypto deliver Drain macOS Stealer Wallets
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

    InfraTrust report warns network management systems under attack

    North Korea’s Fake Job Interviews Drained $11M From 7,000 Crypto Wallets

    Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

    Raiffeisen Expands Crypto Access With Bitpanda

    Arista patches actively exploited VeloCloud Orchestrator zero-day

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    What to do when your Waymo holds up a Secret Service motorcade

    September 23, 2026

    Pornhub age checks investigated by Ofcom

    September 23, 2026

    MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

    September 23, 2026

    Coin Metrics revises 19 months of ETF wallet data but by how much?

    September 23, 2026
    Latest Posts

    Ransom Cartel ransomware creator sentenced to 16 years in prison

    August 5, 2026

    Uber CEO brushes off reports of a Waymo break-up

    August 5, 2026

    Fauci Faces Contempt Vote. Here Are the Legal Issues Involved.

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    What to do when your Waymo holds up a Secret Service motorcade

    September 23, 2026

    Pornhub age checks investigated by Ofcom

    September 23, 2026

    MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.