Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
macOS Malware Steals Crypto via ClickFix Attacks

macOS Malware Steals Crypto via ClickFix Attacks

Posted on August 7, 2026 By CWS

Recent ClickFix attacks have emerged as a significant threat, targeting macOS users with a sophisticated malware designed to steal cryptocurrency and sensitive credentials. This malicious campaign employs a Go-based malware that infiltrates users’ systems, taking aim at browser-stored passwords, Apple iCloud Keychain data, and cached credentials.

Infection Chain and Malware Functionality

The infection begins with a ClickFix command executed within the macOS Terminal app. This action initiates a Bash script that gathers detailed system information before downloading a Mach-O payload suited to the computer’s architecture. The payload, a Go-based stealer, effectively captures and transmits sensitive data to a remote server controlled by cybercriminals.

Security researcher Andrew Brandt from Huntress highlights the malware’s unique capability to gradually deplete cryptocurrency accounts. It achieves this by siphoning funds into wallets managed by the attackers, posing a severe risk to digital assets.

Privilege Escalation and Cryptocurrency Theft

To enhance its effectiveness, the malware seeks to escalate privileges by deceiving users into entering their system credentials through a fabricated system error prompt. Once it gains the necessary access, the malware activates its “DRAIN” routine, targeting cryptocurrency wallets.

This routine is engineered to check for available funds in wallets and redirect them to addresses controlled by the attackers. Multiple cryptocurrency versions of this function exist, affecting Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP.

Infrastructure and Broader Campaigns

The infrastructure supporting these attacks is linked to Aeza Group, a Russian bulletproof hosting provider under international sanctions. This connection highlights the organized nature of the operation, involving sophisticated server staging and command-and-control mechanisms.

ClickFix attacks are not limited to macOS. Variants have exploited Windows systems using legitimate binaries to bypass security measures, and some campaigns employ advanced techniques like WebAssembly and steganography to evade detection. This broadens the scope and impact of these cyber threats.

Conclusion and Future Implications

The rise of ClickFix attacks underscores the urgent need for robust cybersecurity measures to protect digital assets. As attackers continue to refine their methods, staying informed and vigilant is essential to safeguarding personal and financial information.

Proactive measures, including regular system updates and awareness of phishing tactics, are crucial in mitigating the risks posed by these sophisticated malware campaigns. The cybersecurity community must remain alert to evolving threats that challenge both individual and organizational security.

The Hacker News Tags:Aeza Group, Apple Keychain, bulletproof hosting, ClickFix, credential theft, cryptocurrency theft, cryptocurrency wallets, cyber threat, Cybersecurity, Go-based malware, Huntress research, macOS security, malware attacks, malware payload, social engineering

Post navigation

Previous Post: Malware Exploits Windows Hello Keys to Access Entra ID
Next Post: ChainDrop Worm Targets npm Packages for Credential Theft

Related Posts

Vulnerability in Claude Extension Exposes Users to XSS Attacks Vulnerability in Claude Extension Exposes Users to XSS Attacks The Hacker News
Understand Your Real Attack Surface in 45 Days Understand Your Real Attack Surface in 45 Days The Hacker News
UNC6148 Backdoors Fully-Patched SonicWall SMA 100 Series Devices with OVERSTEP Rootkit UNC6148 Backdoors Fully-Patched SonicWall SMA 100 Series Devices with OVERSTEP Rootkit The Hacker News
OpenAI Enhances Cybersecurity with GPT-5.5-Cyber OpenAI Enhances Cybersecurity with GPT-5.5-Cyber The Hacker News
eScan Antivirus Update Servers Compromised to Deliver Multi-Stage Malware eScan Antivirus Update Servers Compromised to Deliver Multi-Stage Malware The Hacker News
Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • ChainDrop Worm Targets npm Packages for Credential Theft
  • macOS Malware Steals Crypto via ClickFix Attacks
  • Malware Exploits Windows Hello Keys to Access Entra ID
  • 800 Malicious npm Packages Spread Cross-Platform Malware
  • Critical Linux SCTP Vulnerability Risks Full Root Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • ChainDrop Worm Targets npm Packages for Credential Theft
  • macOS Malware Steals Crypto via ClickFix Attacks
  • Malware Exploits Windows Hello Keys to Access Entra ID
  • 800 Malicious npm Packages Spread Cross-Platform Malware
  • Critical Linux SCTP Vulnerability Risks Full Root Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark