Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Levi Strauss & Co. says hackers stole corporate data in cyberattack

    August 8, 2026

    Ripple news: New XRP Ledger proposals target $530 million in tokenized Wall Street assets

    August 8, 2026

    After Iran War, Global Straits Will Be Bloodily Contested

    August 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Levi Strauss & Co. says hackers stole corporate data in cyberattack
    • Ripple news: New XRP Ledger proposals target $530 million in tokenized Wall Street assets
    • After Iran War, Global Straits Will Be Bloodily Contested
    • Child among three dead in Russian nightly strikes near Kyiv
    • Samsung Galaxy Watch 9 review: Health data overload, but built for the future
    • Mistral AI Releases Shieldstral 1.0 3B: An Open-Weights Policy-Adaptive Multimodal Safety Classifier Matching Models 7× Its Size
    • ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
    • Bybit Wins Court Support to Trace $1.5B North Korea Hack Funds
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 8, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 07, 2026Malware / Social Engineering

    ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.

    The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that’s compatible with the computer’s CPU architecture.

    “While the malware payload is capable of stealing passwords, its most interesting function is its capability to slowly deplete cryptocurrency accounts, siphoning their contents into accounts under the threat actor’s control,” Huntress security researcher Andrew Brandt said.

    The attack chain begins with pasting a ClickFix command into the Terminal app, triggering the execution of a Bash profiler/loader that collects extensive system details and then retrieves a Mach-O payload that matches the victim’s processor architecture. The payload is a Go-based stealer that can capture browser passwords, Apple Keychain data, and cached credentials and transmit them to a remote server operated by the threat actor.

    Like other macOS stealers, the malware attempts to escalate privileges by prompting the victim to enter their system credentials via a fake prompt under the guise of an “unexpected system error” and restoring damaged system files.

    Cybersecurity

    What’s notable about the malware is that it also packs in a “DRAIN” routine that checks if a cryptocurrency wallet holds funds, and if so, redirects a chunk or all of it to an attacker-controlled wallet. There exist multiple versions of the same function based on the cryptocurrency being targeted. This includes Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple’s XRP.

    “While this may not be a brand new feature, it’s the first time we have seen malware capable of emptying a cryptocurrency wallet that could be used to remove any less than the entire wallet’s value,” Huntress said. “The malware contained separate functions to determine just how much 1% of the wallet’s contents is worth, depending on which cryptocurrency the malware targets.”

    The server staging the malicious payloads and the command-and-control (C2) server all link back to infrastructure belonging to Aeza Group, a Russian bulletproof hosting provider that has been sanctioned by the U.S., the U.K., and Australia for facilitating bad actors.

    The disclosure comes as a number of ClickFix attacks have been reported in recent weeks –

    • A macOS ClickFix campaign distributing MacSync and Atomic Stealer malware that uses a cluster of look-alike domains and implements a server-side browser-fingerprinting and hardware validation gate to conditionally serve the lures only to those visitors whose environment appears consistent with a genuine macOS browser, while blocking crawlers, sandboxes, and some automated analysis tools.
    • A ClickFix variant that abuses Program Compatibility Assistant (“pcalua.exe”), a legitimate Windows binary, as a launcher to bypass parent-process heuristics. “The victim is tricked (via a ClickFix lure) into pasting a crafted command that spawns PowerShell, uses WMI to create cmd.exe, mounts a remote WebDAV share, and loads a malicious DLL through rundll32.exe,” Palo Alto Networks Unit 42 said. “The WebDAV share is exposed over HTTPS via CDN-fronted infrastructure at a per-victim tokenized URL (UUIDv4 path) used to deliver malicious DLL. Once loaded, the DLL is leveraged to deploy infostealer capabilities on the compromised host.”
    • A ClickFix campaign that uses on-the-fly WebAssembly (wasm) module instantiation and steganography through SVG images to evade network-level detection. The activity uses legitimate-but-compromised websites to run injected malicious JavaScript that builds a wasm module that exports URLs from which the SVG files are downloaded to construct the ClickFix URL. “This final ClickFix URL is then dropped onto the DOM with a script tag to display the fake verification page,” Unit 42 said. “The fake verification page presents a checkbox. When the checkbox is clicked, the page presents instructions to paste content into a Run window.”

    The findings also coincide with the discovery of two other stealer campaigns, one which delivers Lumma Stealer via files disguised as 1080p WEBRip and Blu-ray releases of The Odyssey, a newly released movie adaptation of Homer’s ancient Greek epic poem of the same name, and another which uses cracked software and pirated game lures hosted on fake websites via SEO poisoning to drop Remus, a 64-bit variant of Lumma Stealer.

    attacks ClickFix Crypto deliver Drain macOS Stealer Wallets
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Levi Strauss & Co. says hackers stole corporate data in cyberattack

    Metabase SQLi zero-day exploited in customer data-theft attacks

    Treasury Sanctions Crypto Exchanges It Says Laundered Millions for Iran

    3.8 Million Impacted by Unlimited Technology Systems Data Breach

    Practical lessons from deploying AI securely at scale

    Trump Media Abandons Crypto Treasury, Prediction Market Ventures

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Levi Strauss & Co. says hackers stole corporate data in cyberattack

    August 8, 2026

    Ripple news: New XRP Ledger proposals target $530 million in tokenized Wall Street assets

    August 8, 2026

    After Iran War, Global Straits Will Be Bloodily Contested

    August 8, 2026

    Child among three dead in Russian nightly strikes near Kyiv

    August 8, 2026
    Latest Posts

    Angela Rayner rules out rent controls in England

    July 24, 2026

    Merz names Nina Warken chancellery chief in Cabinet reshuffle – POLITICO

    July 24, 2026

    US attacks Iran as Houthis allow Chinese ships to pass: What’s the latest? | US-Israel war on Iran News

    July 24, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Levi Strauss & Co. says hackers stole corporate data in cyberattack

    August 8, 2026

    Ripple news: New XRP Ledger proposals target $530 million in tokenized Wall Street assets

    August 8, 2026

    After Iran War, Global Straits Will Be Bloodily Contested

    August 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.